Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ee751e9642bb791…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 17:31:53 +01:00 Authoring application: mPDF 5.7
MD5: fe5be574333a4f5025a38614914841ae SHA-1: 322c4cfc035502f6dc79299f48e6499e8cb53b5d SHA-256: 3ee751e9642bb79159c212017a00249e2672bd674725f9777fd606f156a3534a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or SEO manipulation tactic. While the document body is heavily obfuscated, the presence of numerous links to external PDF files indicates a likely attempt to distribute content or redirect users to malicious sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099093097097096/Kirsten-s-Craft-Book-by-Jodi-Evert.pdf
    • http://loaminoo.linkpc.net/1090092090099093090/Molly-s-Craft-Book-by-Jodi-Evert.pdf
    • http://loaminoo.linkpc.net/1090092090099092096/Samantha-s-Cook-Book-by-Jodi-Evert.pdf
    • http://loaminoo.linkpc.net/2097095092098092/Writing-Subtext-How-to-craft-subtext-that-develops-characters-boosts-suspense-and-reinforces-theme-Elizabeth-Lyon-on-writing-craft-Book-1-by-Elizabeth-Lyon.pdf
    • http://loaminoo.linkpc.net/8095090099092090/Craft-Objects-Aesthetic-Contexts-Kant-Heidegger-and-Adorno-on-Craft-by-Sandra-Corse.pdf
    • http://loaminoo.linkpc.net/8092091090098091/Craft-Show-Book-by-Rob-Goyette.pdf
    • http://loaminoo.linkpc.net/1095093092097099/Happy-Birthday-Kirsten-A-Springtime-Story-American-Girls-Kirsten-4-by-Janet-Beeler-Shaw.pdf
    • http://loaminoo.linkpc.net/6094094099092099/Kirsten-Fortalt-Til-Annelise-Bistrup-by-Kirsten-Jacobsen.pdf
    • http://loaminoo.linkpc.net/7098097098099094/The-Little-Pink-Book-of-Elegance-by-Jodi-Kahn.pdf
    • http://loaminoo.linkpc.net/1099096092090090/Meet-Kirsten-An-American-Girl-American-Girls-Kirsten-1-by-Janet-Beeler-Shaw.pdf
    • http://loaminoo.linkpc.net/4093099093090097/A-Trail-Through-Time-The-Chronicles-of-St-Mary-s-Book-4-by-Jodi-Taylor.pdf
    • http://loaminoo.linkpc.net/8096090098090095/The-Storyteller-Jodi-Picoult---Review-by-Instant-Book-Club-Parties.pdf
    • http://loaminoo.linkpc.net/8090095095094/Writing-Deep-Point-Of-View-Professional-Techniques-for-Fiction-Authors-Writer-s-Craft-Book-13-by-Rayne-Hall.pdf
    • http://loaminoo.linkpc.net/1090096098091096096/Kirsten-Dunst-211-Success-Facts---Everything-You-Need-to-Know-about-Kirsten-Dunst-by-Tony-Francis.pdf
    • http://loaminoo.linkpc.net/4094097090094092/The-Comic-Book-Story-of-Beer-The-World-s-Favorite-Beverage-from-7000-BC-to-Today-s-Craft-Brewing-Revolution-by-Jonathan-Hennessey.pdf
    • http://loaminoo.linkpc.net/8093097091097090/The-Kirsten-Prout-Handbook---Everything-You-Need-to-Know-about-Kirsten-Prout-by-Emily-Smith.pdf
    • http://loaminoo.linkpc.net/1090092091090095099/Evert-Taube-by-Evert-Taube.pdf
    • http://loaminoo.linkpc.net/1090092091090095097/Evert-Lundquist-by-Evert-Lundquist.pdf
    • http://loaminoo.linkpc.net/1090092091090096092/Chris-Evert-by-Jay-H-Smith.pdf
    • http://loaminoo.linkpc.net/1090092090099092098/The-Reindeer-Wish-by-Lori-Evert.pdf
    • http://loaminoo.linkpc.net