Malicious PDF — malware analysis report

Static analysis result for SHA-256 47543523b878a9ab…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 04:12:29 +01:00 Authoring application: mPDF 5.7
MD5: 655be98a7ff5fc9879bb7ec151f741d2 SHA-1: e7f233c6a7017f655f7b196c7f5bf6dbff601a1c SHA-256: 47543523b878a9ab06b2647dcc3471a68d95aeb210207b426d48125353a54ddf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a link farm or redirection mechanism, which is a common tactic for distributing malicious payloads or for SEO manipulation. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097090091094096/The-Empresses-of-Constantinople-by-Joseph-McCabe.pdf
    • http://loaminoo.linkpc.net/2099093091092090/The-Nightmares-on-Elm-Street-Part-4-The-Dream-Master-Part-5-The-Dream-Child-by-Joseph-Locke.pdf
    • http://loaminoo.linkpc.net/6095099096090095/Night-Shadows-A-Rebekah-McCabe-Mystery-Rebekah-McCabe-Mysteries-Book-1-by-Bill-Craig.pdf
    • http://loaminoo.linkpc.net/2092094094094/The-Dandelion-Seed-s-Big-Dream-by-Joseph-Anthony.pdf
    • http://loaminoo.linkpc.net/9091095092090/I-Have-a-Dream-by-Martin-Luther-King-Jr-.pdf
    • http://loaminoo.linkpc.net/8094092094099092/A-Dream-Called-Marilyn-by-Mercedes-King.pdf
    • http://loaminoo.linkpc.net/1090090099098096097/King-Solomon-s-Dream-1-Kings-3-5-15-1-Chronicles-1-7-13-by-J-Eger.pdf
    • http://loaminoo.linkpc.net/4091090098095098/Dream-a-Little-Christmas-Dream-Dream-a-Little-Dream-1-5-by-Giovanna-Fletcher.pdf
    • http://loaminoo.linkpc.net/9092096092098095/King-Abdallah-And-Palestine-A-Territorial-Ambition-by-Joseph-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092098099/King-Abdallah-and-Palestine-A-Territorial-Ambition-by-Joseph-Nevo.pdf
    • http://loaminoo.linkpc.net/8099093095098096/DREAM-BIG-How-Jorge-Paulo-Lemann-Marcel-Telles-and-Beto-Sicupira-Acquired-Anheuser-Busch-Burger-King-and-Heinz-and-Revolutionized-Brazilian-Capitalism-by-Cristiane-Correa.pdf
    • http://loaminoo.linkpc.net/2091094097092096/Blu-s-Hanging-by-Lois-Ann-Yamanaka.pdf
    • http://loaminoo.linkpc.net/1092098098097093/Hanging-Fire-by-Phyllis-Webb.pdf
    • http://loaminoo.linkpc.net/6093098096093/Journey-to-a-Hanging-by-Peter-Wells.pdf
    • http://loaminoo.linkpc.net/1092094094098090/Leave-Her-Hanging-by-Harry-St-John.pdf
    • http://loaminoo.linkpc.net/1090091099097096/Hanging-Fields-by-Steven-Maxwell.pdf
    • http://loaminoo.linkpc.net/1097090093095097/Hanging-On-Awakenings-2-by-Michele-Zurlo.pdf
    • http://loaminoo.linkpc.net/2094095098091092/A-Good-Hanging-by-Russel-K-Stevens.pdf
    • http://loaminoo.linkpc.net/2094090097097095/The-Butcher-Boy-by-Patrick-McCabe.pdf
    • http://loaminoo.linkpc.net/5091096093096095/Victims-by-Eugene-McCabe.pdf
    • http://loaminoo.linkpc.net/9092096092098095/King-Abdallah-And-Palestine-A-Terri