Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b02ac169d8a36bc…

MALICIOUS

PDF

23.8 KB Created: 2019-04-30 02:00:17 +01:00 Authoring application: mPDF 5.7
MD5: 5dcd07838407dc11f0e2928a70f3c72e SHA-1: 79507d7c56fa2caa4c5eecf541d94c22e303d8c2 SHA-256: 7b02ac169d8a36bce93133d9d816a95806500a01817c6b4d3b730b25f7fea654
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and nature of these links suggest a potential SEO manipulation or a link farm intended to redirect users to malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8092095096097095/United-We-Fall-The-Crisis-Of-Democracy-In-Canada-by-Susan-Delacourt.pdf
    • http://loaminoo.linkpc.net/6093099099092091/Canada-and-Aboriginal-Canada-Today---Le-Canada-Et-Le-Canada-Autochtone-Aujourdahui-Changing-the-Course-of-History---Changer-Le-Cours-de-Lahistoire-by-Paul-Martin.pdf
    • http://loaminoo.linkpc.net/6090099091097090/Dismantling-Democracy-Stifling-debate-and-dissent-in-Canada-by-voices-voix.pdf
    • http://loaminoo.linkpc.net/1090099092099093095/Hunger-and-Fury-The-Crisis-of-Democracy-in-the-Balkans-by-Jasmin-Mujanovic.pdf
    • http://loaminoo.linkpc.net/2094098091091090/Missing-411-Western-United-States-and-Canada-by-David-Paulides.pdf
    • http://loaminoo.linkpc.net/7092092099096094/The-U-S-of-EH-How-Canada-Secretly-Controls-the-United-States-and-Why-That-s-OK-by-Kerry-Colburn.pdf
    • http://loaminoo.linkpc.net/3090095098096099/Regions-Apart-The-Four-Societies-of-Canada-and-the-United-States-by-Edward-Grabb.pdf
    • http://loaminoo.linkpc.net/2093095091090/The-Right-To-Vote-The-Contested-History-Of-Democracy-In-The-United-States-by-Alexander-Keyssar.pdf
    • http://loaminoo.linkpc.net/7099098093093097/People-are-Seeing-Something-a-Survey-of-Lake-Monsters-in-the-United-States-and-Canada-by-Denver-Michaels.pdf
    • http://loaminoo.linkpc.net/8091097092099093/Weeds-of-Canada-and-the-Northern-United-States-A-Guide-for-Identification-by-France-Royer.pdf
    • http://loaminoo.linkpc.net/8095090099091097/Nationalism-and-Literature-The-Politics-of-Culture-in-Canada-and-the-United-States-by-Sarah-M-Corse.pdf
    • http://loaminoo.linkpc.net/1095097091094098/Crisis-At-Sea-The-United-States-Navy-in-European-Waters-in-World-War-I-by-William-N-Still-Jr-.pdf
    • http://loaminoo.linkpc.net/5091094096095096/The-Traffic-in-Babies-Cross-Border-Adoption-and-Baby-Selling-Between-the-United-States-and-Canada-1930-1972-by-Karen-Balcom.pdf
    • http://loaminoo.linkpc.net/1091090091099090/The-United-States-and-the-Far-East-Crisis-of-1933-1938-From-the-Manchurian-Incident-through-the-Initial-Stage-of-the-Undeclared-Sino-Japanese-War-by-Dorothy-Borg.pdf
    • http://loaminoo.linkpc.net/8095092090095/Fruitless-Fall-The-Collapse-of-the-Honey-Bee-and-the-Coming-Agricultural-Crisis-by-Rowan-Jacobsen.pdf
    • http://loaminoo.linkpc.net/1096097093093092/Coming-to-Canada-Building-a-Life-in-a-New-Land-by-Susan-Hughes.pdf
    • http://loaminoo.linkpc.net/4096091091092097/The-Rise-and-Fall-of-Nations-Forces-of-Change-in-the-Post-Crisis-World-by-Ruchir-Sharma.pdf
    • http://loaminoo.linkpc.net/7097092096096091/The-Fateful-History-of-Fannie-Mae-New-Deal-Birth-to-Mortgage-Crisis-Fall-by-James-R-Hagerty.pdf
    • http://loaminoo.linkpc.net/8098097097096095/Rise-of-Ethnic-Politics-in-Nepal-Democracy-in-the-Margins-by-Susan-I-Hangen.pdf
    • http://loaminoo.linkpc.net/3094093095090090/The-Black-Plagues-United-We-Stand-Divided-We-Fall-by-Kennyrich-Fomunung.pdf