Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b8f02e0dbff858f…

MALICIOUS

PDF

18.8 KB Created: 2019-05-07 04:21:15 +01:00 Authoring application: mPDF 5.7
MD5: 5143b60f90ae2c1e1db30a030ac76133 SHA-1: b14eb8941c3a169e7d33b8a5fb10f2c7d37ea2e4 SHA-256: 3b8f02e0dbff858f65d6a9cb8c2069f3526d896b4a0d7b047e9ea149e231b948
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a large number of embedded external links, suggesting a link farm or distribution mechanism. While many of the linked URLs are marked as benign, the sheer volume and the nature of the heuristic indicate a potentially malicious intent to manipulate search engine results or distribute further content. No scripts were extracted, and the document body was unreadable, limiting further analysis.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/5090098099096/The-Nature-of-the-Place-A-Study-of-Great-Plains-Fiction-by-Diane-Dufva-Quantic.pdf
    • http://loaminoo.linkpc.net/2092096090095091/A-Sandhills-Reader-30-Years-of-Great-Writing-from-the-Great-Plains-by-Ted-Kooser.pdf
    • http://loaminoo.linkpc.net/6093099093095/Great-Plains-by-Ian-Frazier.pdf
    • http://loaminoo.linkpc.net/8095093098090099/A-Cowboy-for-Caleb-Great-Plains-Shifters-1-by-L-C-Davis.pdf
    • http://loaminoo.linkpc.net/1091097094094091094/Computerized-Accounting-Using-Great-Plains-Dynamic-by-Arens.pdf
    • http://loaminoo.linkpc.net/3092094090093/My-ntonia-Great-Plains-Trilogy-3-by-Willa-Cather.pdf
    • http://loaminoo.linkpc.net/2093095096094/Where-the-Buffalo-Roam-Restoring-America-s-Great-Plains-by-Anne-Matthews.pdf
    • http://loaminoo.linkpc.net/5096098094092090/My-Tiny-Vegas-Life-Between-the-Sangre-de-Christo-Mountains-and-the-Great-Plains-by-Birdie-Jaworski.pdf
    • http://loaminoo.linkpc.net/4092091090096092/Quest-for-Quivira-Spanish-Explorers-on-the-Great-Plains-1540-1821-by-Thomas-E-Ch-vez.pdf
    • http://loaminoo.linkpc.net/4092090095095095/The-Mystic-Warriors-of-the-Plains-The-Culture-Arts-Crafts-and-Religion-of-the-Plains-Indians-by-Thomas-E-Mails.pdf
    • http://loaminoo.linkpc.net/4095094094096094/It-Was-Like-My-Trying-to-Have-a-Tender-Hearted-Nature-A-Novella-and-Stories-by-Diane-Williams.pdf
    • http://loaminoo.linkpc.net/5096097094091091/The-Dead-Place-Ben-Cooper-amp-Diane-Fry-6-by-Stephen-Booth.pdf
    • http://loaminoo.linkpc.net/1098093094095/The-Sacred-Balance-Rediscovering-Our-Place-in-Nature-by-David-Suzuki.pdf
    • http://loaminoo.linkpc.net/5094090090095/Written-in-Stone-Evolution-the-Fossil-Record-and-Our-Place-in-Nature-by-Brian-Switek.pdf
    • http://loaminoo.linkpc.net/4099094097097091/Wildbranch-An-Anthology-of-Nature-Environmental-and-Place-based-Writing-by-Florence-Caplow.pdf
    • http://loaminoo.linkpc.net/7095095097090094/The-Handbook-of-Nature-Study-by-Anna-Botsford-Comstock.pdf
    • http://loaminoo.linkpc.net/4092096097095096/Peter-the-Great-by-Diane-Stanley.pdf
    • http://loaminoo.linkpc.net/7094096090091099/Queneau-s-Fiction-An-Introductory-Study-by-Christopher-Shorley.pdf
    • http://loaminoo.linkpc.net/2090091094096094/High-Plains-Promise-Love-on-the-High-Plains-2-by-Simone-Beaudelaire.pdf
    • http://loaminoo.linkpc.net/1094096098091093/High-Plains-Holiday-Love-on-the-High-Plains-1-by-Simone-Beaudelaire.pdf