Malicious PDF — malware analysis report

Static analysis result for SHA-256 50e58d48f53a32fa…

MALICIOUS

PDF

15.3 KB Created: 2019-04-30 05:28:10 +01:00 Authoring application: mPDF 5.7
MD5: 4ea39f3ba03f2cb296bbd09ee5aa64c9 SHA-1: 1229753d765aa2d306fe5472ec62ec7b2b4da38c SHA-256: 50e58d48f53a32fa51b2406101500241f70c575ba872339cd5ff61f02128ea2f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, indicative of a link farm or SEO spamming technique. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to manipulate search engine results or potentially lead users to malicious sites. No scripts were extracted, limiting further analysis of the file's direct execution capabilities.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090090097098091098/Knight-in-Leather-Hearth-Motel-2-by-Holley-Trent.pdf
    • http://loaminoo.linkpc.net/1090091090096095097/Following-Fabian-Shrew-amp-Company-4-by-Holley-Trent.pdf
    • http://loaminoo.linkpc.net/4097096098098093/Colleen-s-Choice-Emerald-Springs-Legacy-2-by-Holley-Trent.pdf
    • http://loaminoo.linkpc.net/3092098092097098/Knight-In-Black-Leather-by-Gail-Dayton.pdf
    • http://loaminoo.linkpc.net/8090097092091090/Motel-Bizarre-Tales-from-the-No-Tell-Motel-by-Stephanie-Crabe.pdf
    • http://loaminoo.linkpc.net/3095094096093097/Trent-s-Last-Case-Philip-Trent-1-by-E-C-Bentley.pdf
    • http://loaminoo.linkpc.net/1090090097097092098/Motel-6-Motel-6-1-by-Delilah-Mae.pdf
    • http://loaminoo.linkpc.net/4094092092093097/One-Night-with-an-Earl-A-House-of-Trent-Novella-House-of-Trent-2-5-by-Jennifer-Haymore.pdf
    • http://loaminoo.linkpc.net/7097097095098095/Leather-and-Pleasure-Leather-and-Pleasure-1-by-Jennifer-Labelle.pdf
    • http://loaminoo.linkpc.net/4091099099092/Eden-by-David-Holley.pdf
    • http://loaminoo.linkpc.net/8092098098098095/Eloge-de-L-Odorat-by-Andr-Holley.pdf
    • http://loaminoo.linkpc.net/2099096099094/The-Wheel-amp-the-Hearth-by-Lucia-Moore.pdf
    • http://loaminoo.linkpc.net/5099090091090090/A-Hearth-s-Warming-Gift-by-Togashi.pdf
    • http://loaminoo.linkpc.net/2092092093095098/The-Cloister-and-the-Hearth-by-Charles-Reade.pdf
    • http://loaminoo.linkpc.net/2097097099094092/Yours-Mine-and-Howls-Werewolves-in-Love-2-by-Kinsey-W-Holley.pdf
    • http://loaminoo.linkpc.net/4098099098092096/The-Devil-s-Hearth-Fever-Devilin-1-by-Phillip-DePoy.pdf
    • http://loaminoo.linkpc.net/1091095094091092090/Heart-of-Dixie-A-Hearth-And-Home-Spinoff-by-Mychael-Black.pdf
    • http://loaminoo.linkpc.net/1090098098093097092/Hearth-and-Home-Images-of-Women-in-the-Mass-Media-by-Gaye-Tuchman.pdf
    • http://loaminoo.linkpc.net/1090094099095096093/Cottage-Witchery-Natural-Magick-for-Hearth-and-Home-by-Ellen-Dugan.pdf
    • http://loaminoo.linkpc.net/4094096091094091/Robbing-the-Bees-A-Biography-of-Honey--The-Sweet-Liquid-Gold-that-Seduced-the-World-by-Holley-Bishop.pdf
    • http://loaminoo.linkpc.net/5099090091090090/A-Hearth-s-Wa