Malicious PDF — malware analysis report

Static analysis result for SHA-256 3953b6b16812f821…

MALICIOUS

PDF

15.2 KB Created: 2019-04-30 18:35:40 +01:00 Authoring application: mPDF 5.7
MD5: 7b70229c882f3ca5244293d07cfea34f SHA-1: 43e6d5e94f7c60e6436406ef9a93ff2ef1e21cbb SHA-256: 3953b6b16812f821c05ff43b05fe8659de08ab79237a83393566ba061d87c97e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The heuristic PDF_SEO_LINK_FARM specifically identified this behavior. While the URLs themselves are marked as confirmed benign, the sheer volume and the nature of the hosting domain suggest a malicious intent to drive traffic or potentially serve other payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099094094092091/GREYSTONE-by-Howard-A-Sherman.pdf
    • http://loaminoo.linkpc.net/1090099094092099091/The-Greystone-Girls-Greystone-1-by-Joy-Francis.pdf
    • http://loaminoo.linkpc.net/1090099094094096090/The-Heart-of-the-Greystone-by-MK-Brown.pdf
    • http://loaminoo.linkpc.net/1090099094092098098/Casino-Greystone-by-Louisa-Bronte.pdf
    • http://loaminoo.linkpc.net/1090099094092098095/Courage-Greystone-8-by-Taylor-Longford.pdf
    • http://loaminoo.linkpc.net/1090099094092093090/Truthsight-Outcast-Mage-1-by-Miriam-Greystone.pdf
    • http://loaminoo.linkpc.net/1090099094094095098/Charlotte-Greystone-by-Peggy-Reid-Rhodes.pdf
    • http://loaminoo.linkpc.net/1090099094094092096/Greystone-s-Creative-Hands-Vol-1-by-Beverley-Hilton.pdf
    • http://loaminoo.linkpc.net/1090099094094091092/In-the-Fog-The-Final-Chronicle-of-Greystone-Bay-by-Charles-L-Grant.pdf
    • http://loaminoo.linkpc.net/1090099094094095092/The-Greystone-Bundle-Books-1-4-by-Taylor-Longford.pdf
    • http://loaminoo.linkpc.net/1090099094094092090/Freedom-Trail-to-Greystone-by-Louisa-Bronte.pdf
    • http://loaminoo.linkpc.net/1090099094094092094/The-Doctor-Mike-Greystone-Book-2-by-Michael-Sigurdsson.pdf
    • http://loaminoo.linkpc.net/1090099094095092090/The-Ghost-of-Greystone-Grange-by-Arthur-William-Beckett.pdf
    • http://loaminoo.linkpc.net/1090099094094092095/The-Hunt-Mike-Greystone-Book-1-by-Michael-Sigurdsson.pdf
    • http://loaminoo.linkpc.net/9097090091096095/Sanft-ber-hrte-Narben-Unsterblich-geliebt-3-by-Lara-Greystone.pdf
    • http://loaminoo.linkpc.net/1090099094092098093/Grizzly-Bear-s-Bride-Greystone-Shifters-1-by-Viola-Rivard.pdf
    • http://loaminoo.linkpc.net/4097090099092097/The-Shadow-at-Greystone-Chase-An-Angela-Marchmont-Mystery-Book-10-by-Clara-Benson.pdf
    • http://loaminoo.linkpc.net/2098099099098094/Time-Burial-The-Collected-Fantasy-Tales-of-Howard-Wandrei-by-Howard-Wandrei.pdf
    • http://loaminoo.linkpc.net/2098099096093091/Waterfront-Fists-And-Others-The-Collected-Fight-Stories-Of-Robert-E-Howard-by-Robert-E-Howard.pdf
    • http://loaminoo.linkpc.net/8092094090098/Linda-Howard-Collection-Heartbreaker-White-Lies-by-Linda-Howard.pdf
    • http://loaminoo.linkpc.net/1090099094095092090/The-Ghost-of-Greystone-Grange-by-Arthur-William-Beckett