Malicious PDF — malware analysis report

Static analysis result for SHA-256 42f7fc07ebafb324…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 05:20:17 +01:00 Authoring application: mPDF 5.7
MD5: 59f808f9619cc2d6f8467dd080797dfe SHA-1: 3023baeb862e6365f3e6a0e5de8270bcd93fb445 SHA-256: 42f7fc07ebafb3242108844e79399431f67cf328fe4aa18cb994e81e8dfa51e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to act as a distribution point for other threats. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091092094091090/Sex-at-Dawn-How-We-Mate-Why-We-Stray-and-What-It-Means-for-Modern-Relationships-by-Christopher-Ryan.pdf
    • http://loaminoo.linkpc.net/5091099099098095/Classics-Transformed-Schools-Universities-and-Society-in-England-1830-1960-by-Christopher-Stray.pdf
    • http://loaminoo.linkpc.net/9094093090090095/The-Education-of-T-C-Mits-What-modern-mathematics-means-to-you-by-Lillian-R-Lieber.pdf
    • http://loaminoo.linkpc.net/5092095097/The-Play-Mate-Roommates-2-by-Kendall-Ryan.pdf
    • http://loaminoo.linkpc.net/6092094097/The-Soul-Mate-Roommates-4-by-Kendall-Ryan.pdf
    • http://loaminoo.linkpc.net/3098098090094095/The-Room-Mate-Roommates-1-by-Kendall-Ryan.pdf
    • http://loaminoo.linkpc.net/3099091093094096/Buddha-amp-Love-Timeless-Wisdom-for-Modern-Relationships-by-Ole-Nydahl.pdf
    • http://loaminoo.linkpc.net/1092097097090095/Because-I-am-Ryan-s-Mommy-by-Dawn-M-Donahue.pdf
    • http://loaminoo.linkpc.net/3099090092091097/The-Lucifer-Gospel-Finn-Ryan-2-by-Paul-Christopher.pdf
    • http://loaminoo.linkpc.net/1090095095098098/Michelangelo-s-Notebook-Finn-Ryan-1-by-Paul-Christopher.pdf
    • http://loaminoo.linkpc.net/3097093094091097/Royally-Yours-A-Modern-Day-Valentine-s-Fairytale-by-Jude-Ryan.pdf
    • http://loaminoo.linkpc.net/3095097097093092/Modern-Hero-Ryan-Wolf-1-by-Jake-Menne.pdf
    • http://loaminoo.linkpc.net/2091099096095/Dawn-to-the-West-Japanese-Literature-of-the-Modern-Era-Fiction-by-Donald-Keene.pdf
    • http://loaminoo.linkpc.net/1098096094093090/Fifth-Avenue-5-A-M-Audrey-Hepburn-Breakfast-at-Tiffany-s-and-the-Dawn-of-the-Modern-Woman-by-Sam-Wasson.pdf
    • http://loaminoo.linkpc.net/2093097096099098/The-Hunt-for-the-Dawn-Monkey-Unearthing-the-Origins-of-Monkeys-Apes-and-Humans-by-Christopher-Beard.pdf
    • http://loaminoo.linkpc.net/3093093092097096/Love-Means-Renewal-Love-Means-Series-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/1098096099098091/America-1908-The-Dawn-of-Flight-the-Race-to-the-Pole-the-Invention-of-the-Model-T-and-the-Making-of-a-Modern-Nation-by-Jim-Rasenberger.pdf
    • http://loaminoo.linkpc.net/4091098096099094/Noragami-Stray-God-Vol-1-Noragami-Stray-God-1-by-Adachitoka.pdf
    • http://loaminoo.linkpc.net/2099099094099097/Adrian-s-Forgotten-Mate-The-Pregnant-Mate-2-by-Marcy-Jacks.pdf
    • http://loaminoo.linkpc.net/1090099093090091095/Samurai-Revolution-The-Dawn-of-Modern-Japan-Seen-Through-the-Eyes-of-the-Shogun-s-Last-Samurai-by-Romulus-Hillsborough.pdf
    • http://loaminoo.linkpc.net/3098098090094095/The-Room