Malicious PDF — malware analysis report

Static analysis result for SHA-256 367d083125cb11f8…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 17:53:50 +01:00 Authoring application: mPDF 5.7
MD5: 49bc4ec4da47983ea21939d9f6598df3 SHA-1: f770c27976352196888791e54976ab6bbc716b82 SHA-256: 367d083125cb11f83ce320380045b59d0005e6e9874787260821e5be5ddf489f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a tactic to drive traffic to potentially malicious or SEO-manipulated content. The primary attack pattern observed is the mass distribution of external links within the PDF.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090096091098092/The-Bad-Boys-Reluctant-Woman-The-Law-Castle-Bad-Boys-2-by-Sam-Crescent.pdf
    • http://loaminoo.linkpc.net/1091099091098098096/Real-Boys-Boys-Will-Do-Boys-6-by-Nica-Berry.pdf
    • http://loaminoo.linkpc.net/1099092091097096/The-Way-of-Boys-Raising-Healthy-Boys-in-a-Challenging-and-Complex-World-by-Anthony-Rao.pdf
    • http://loaminoo.linkpc.net/6099093090099098/Boys-Will-Be-Boys-Breaking-the-Link-Between-Masculinity-and-Violence-by-Myriam-Miedzian.pdf
    • http://loaminoo.linkpc.net/2096097099091090/Boys-Adrift-The-Five-Factors-Driving-the-Growing-Epidemic-of-Unmotivated-Boys-and-Underachieving-Young-Men-by-Leonard-Sax.pdf
    • http://loaminoo.linkpc.net/1094090097097091/Boys-Will-Be-Boys-The-Glory-Days-and-Party-Nights-of-the-Dallas-Cowboys-Dynasty-by-Jeff-Pearlman.pdf
    • http://loaminoo.linkpc.net/6097096098091095/The-Boys-Tomo-1-El-nombre-del-juego-The-Boys-1-by-Garth-Ennis.pdf
    • http://loaminoo.linkpc.net/3099099096091091/Raising-Boys-Why-Boys-Are-Different-and-How-to-Help-Them-Become-Happy-and-Well-Balanced-Men-by-Steve-Biddulph.pdf
    • http://loaminoo.linkpc.net/1099092098090090/Game-Boys-Boys-in-Love-1-by-Rochelle-H-Ragnarok.pdf
    • http://loaminoo.linkpc.net/1092090097092/Who-Needs-Boys-The-Girlfriend-s-Guide-to-Boys-3-by-Stephie-Davis.pdf
    • http://loaminoo.linkpc.net/4096099097092094/Real-Boys-Kiss-Boys-by-Joe-Filippone.pdf
    • http://loaminoo.linkpc.net/7095092091095095/Boys-Over-Flowers-Hana-Yori-Dango-Vol-32-Boys-Over-Flowers-32-by-Y-ko-Kamio.pdf
    • http://loaminoo.linkpc.net/7095092090099091/Boys-Over-Flowers-Hana-Yori-Dango-Vol-8-Boys-Over-Flowers-8-by-Y-ko-Kamio.pdf
    • http://loaminoo.linkpc.net/7095092090090099/Boys-Over-Flowers-Hana-Yori-Dango-Vol-4-Boys-Over-Flowers-4-by-Y-ko-Kamio.pdf
    • http://loaminoo.linkpc.net/3091092097093092/Awesome-Adventure-Stories-for-Boys-19-Adventurous-Stories-for-Boys-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/7095092090091091/Boys-Over-Flowers-Hana-Yori-Dango-Vol-7-Boys-Over-Flowers-7-by-Y-ko-Kamio.pdf
    • http://loaminoo.linkpc.net/7095092091094098/Boys-Over-Flowers-Hana-Yori-Dango-Vol-22-Boys-Over-Flowers-22-by-Y-ko-Kamio.pdf
    • http://loaminoo.linkpc.net/8099099090099097/Bareback-Boys-III-Volume-3-The-Bareback-Boys-Club-for-Men-3-by-John-Lucke.pdf
    • http://loaminoo.linkpc.net/8099099090099092/Bareback-Boys-Volume-1-The-Bareback-Boys-Club-for-Men-1-by-John-Lucke.pdf
    • http://loaminoo.linkpc.net/2090092090095096/Bad-Boys-After-Dark-Dylan-Bad-Boys-After-Dark-2-Billionaires-After-Dark-6-Love-in-Bloom-48-by-Melissa-Foster.pdf
    • http://loaminoo.linkpc.net/6097096098091095/The-Boys-Tomo-1-El-nombre