Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b8583621e817b14…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 19:21:19 +01:00 Authoring application: mPDF 5.7
MD5: 42a2b7a1fe46b3df566913394cab9c79 SHA-1: 060453cbbc50418aa942af4fe420de06eeea3909 SHA-256: 3b8583621e817b14d316679452b0149e7180589e19c98126bea46ce5b3d5a87f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm. The URLs themselves appear to be benign, but the sheer volume and structure suggest a malicious intent to drive traffic or host further malicious payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090098097093099096/Sociological-Theory-Values-and-Sociocultural-Change-Essays-in-Honor-of-Pitirim-A-Sorokin-by-Harriet-Martineau.pdf
    • http://loaminoo.linkpc.net/1090098097091093093/Social-and-Cultural-Dynamics-A-Study-of-Change-in-Major-Systems-of-Art-Truth-Ethics-Law-and-Social-Relationships-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1090098097091094094/Man-and-Society-in-Calamity-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1090098097093094092/The-Reconstruction-of-Humanity-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1090098097092092097/Power-and-Morality-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1090098097093098095/Systematic-Source-Book-in-Rural-Sociology-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/2095096094095096/Ways-Power-Of-Love-Techniques-Of-Moral-Transformation-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1090098097093094097/Love-altruism-and-world-crisis-The-challenge-of-Pitirim-Sorokin-by-Joseph-Allen-Matter.pdf
    • http://loaminoo.linkpc.net/1090098097093098092/Altruistic-Love-A-Study-of-American-Good-Neighbors-and-Christian-Saints-by-Pitirim-A-Sorokin.pdf
    • http://loaminoo.linkpc.net/1091091098099098091/Feats-On-The-Fiord-by-Harriet-Martineau.pdf
    • http://loaminoo.linkpc.net/9092098090097094/Quantum-Field-Theory-and-Beyond-Essays-in-Honor-of-Wolfhart-Zimmermann-by-Erhard-Seiler.pdf
    • http://loaminoo.linkpc.net/6098090091095097/Guide-to-Keswick-and-Its-Environs-by-Harriet-Martineau.pdf
    • http://loaminoo.linkpc.net/7098095097097/Being-Mentally-Ill-A-Sociological-Theory-by-Thomas-J-Scheff.pdf
    • http://loaminoo.linkpc.net/3093090098092098/The-Structure-of-Sociological-Theory-by-Jonathan-H-Turner.pdf
    • http://loaminoo.linkpc.net/1093099095096095/The-Sacred-Canopy-Elements-of-a-Sociological-Theory-of-Religion-by-Peter-L-Berger.pdf
    • http://loaminoo.linkpc.net/1091097094095091093/Emotions-and-Social-Change-Historical-and-Sociological-Perspectives-by-David-Lemmings.pdf
    • http://loaminoo.linkpc.net/4099092097098090/The-Mother-Dance-How-Children-Change-Your-Life-by-Harriet-Lerner.pdf
    • http://loaminoo.linkpc.net/1091094090094092098/Organizational-Theory-Design-and-Change-by-Gareth-R-Jones.pdf
    • http://loaminoo.linkpc.net/1090091090091097094/Facets-of-Fieldwork-Essays-in-Honor-of-Jurg-Wassmann-by-Alexis-Th-Poser.pdf
    • http://loaminoo.linkpc.net/9099097092091093/The-Grammar-Pragmatics-Interface-Essays-in-Honor-of-Jeanette-K-Gundel-by-Nancy-Hedberg.pdf
    • http://loaminoo.linkpc.net