Malicious PDF — malware analysis report

Static analysis result for SHA-256 57570f7e62d1abbd…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 17:23:47 +01:00 Authoring application: mPDF 5.7
MD5: 6da917fa33e9670d46c3850a24f4a9d8 SHA-1: 8414288e0e8f3e1075f3bf17e1af81d0a77a3896 SHA-256: 57570f7e62d1abbdbab3ad3bfdc0cd1ca3f9378ce324e8dfa1f66721fb3f57ee
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to direct users to external resources. No scripts were extracted from this sample, limiting further analysis of its behavior.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095094091098/How-to-Talk-Dirty-and-Influence-People-by-Lenny-Bruce.pdf
    • http://loaminoo.linkpc.net/2094099093098095/I-ll-Seize-the-Day-Tomorrow-by-Jonathan-Goldstein.pdf
    • http://loaminoo.linkpc.net/8094093096093/Puppy-Chow-is-Better-Than-Prozac-The-True-Story-of-a-Man-and-the-Dog-Who-Saved-His-Life-by-Bruce-Goldstein.pdf
    • http://loaminoo.linkpc.net/1091098093097092091/Over-My-Dead-Body-by-Bruce-A-Borders.pdf
    • http://loaminoo.linkpc.net/1096097094099099/Perfectly-Healthy-Man-Drops-Dead-by-Bruce-Hartman.pdf
    • http://loaminoo.linkpc.net/3093098092096098/The-Plain-of-Dead-Cities-A-Syrian-Tale-by-Bruce-McLaren.pdf
    • http://loaminoo.linkpc.net/1090091091098097093/Diagnosis-Dead-by-Jonathan-Kellerman.pdf
    • http://loaminoo.linkpc.net/3092091095097094/God-Is-Dead-Volume-1-by-Jonathan-Hickman.pdf
    • http://loaminoo.linkpc.net/6091097094093/Dead-of-Night-Dead-of-Night-1-by-Jonathan-Maberry.pdf
    • http://loaminoo.linkpc.net/8096095099096/Dead-Man-s-Song-Pine-Deep-2-by-Jonathan-Maberry.pdf
    • http://loaminoo.linkpc.net/3095090093090097/Goodbye-to-the-Dead-Jonathan-Stride-7-by-Brian-Freeman.pdf
    • http://loaminoo.linkpc.net/5098095094093098/Goodbye-to-the-Dead-Jonathan-Stride-7-by-Brian-Freeman.pdf
    • http://loaminoo.linkpc.net/3093098099098093/Lenny-for-Your-Thoughts-by-Anyta-Sunday.pdf
    • http://loaminoo.linkpc.net/1090093095090099096/The-Love-Bombing-of-Lenny-the-Lemming-by-B-F-Moloney.pdf
    • http://loaminoo.linkpc.net/4092096099098097/House-of-Nails-A-Memoir-of-Life-on-the-Edge-by-Lenny-Dykstra.pdf
    • http://loaminoo.linkpc.net/1090098095096098/Tales-of-the-Rot-amp-Ruin-Rot-amp-Ruin-Dust-amp-Decay-Dead-amp-Gone-Flesh-amp-Bone-by-Jonathan-Maberry.pdf
    • http://loaminoo.linkpc.net/5093090093092098/Bruce-s-History-Lessons-The-First-Five-Years-2001---2006-by-Bruce-Kauffmann.pdf
    • http://loaminoo.linkpc.net/2096098092093097/As-Luck-Would-Have-It-by-Mark-A-Goldstein.pdf
    • http://loaminoo.linkpc.net/3090097095091/The-Red-Magician-by-Lisa-Goldstein.pdf
    • http://loaminoo.linkpc.net/1093091090091097/The-Red-Magician-by-Lisa-Goldstein.pdf
    • http://loaminoo.linkpc.net/8096095099096/Dead-Man-s-Song-Pine-Deep-2-by-Jonat