Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a18ad450c1a0c3d…

MALICIOUS

PDF

19.7 KB Created: 2019-05-06 16:42:10 +01:00 Authoring application: mPDF 5.7
MD5: 6a4f8a7596d2a7e8edf256bb75372168 SHA-1: c69dd0e8e8f3e0966145d4e95c4046300974a962 SHA-256: 8a18ad450c1a0c3d58e95ab157bfc02d06c00704d96456ba8ec8e4e2434b76bf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' directly identifies this behavior. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic indicate a malicious intent to direct users to a potentially harmful collection of resources. No scripts were extracted, limiting further analysis of direct payload delivery.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093097090095097/Footsteps-Adventures-of-a-Romantic-Biographer-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/2091092092093/The-Age-of-Wonder-How-the-Romantic-Generation-Discovered-the-Beauty-and-Terror-of-Science-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/8094098092093096/The-Sherlock-Holmes-Illustrated-Omnibus-The-Adventures-of-Sherlock-Holmes-the-Memoirs-of-Sherlock-Holmes-the-Hound-of-the-Baskervilles-the-Return-of-Sherlock-Holmes-A-Facsimile-of-the-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/4091097097095098/First-Footsteps-in-East-Africa-by-Richard-Francis-Burton.pdf
    • http://loaminoo.linkpc.net/3092090090091091/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/6091099091097092/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/7095093098095097/A-Paris-Year-My-Day-to-Day-Adventures-in-the-Most-Romantic-City-in-the-World-by-Janice-Macleod.pdf
    • http://loaminoo.linkpc.net/4093097095095095/Paradise-Interrupted-Romantic-Adventures-Backpacking-Across-the-Philippines-Baby-in-Tow-by-Sarah-Bringhurst.pdf
    • http://loaminoo.linkpc.net/8091091092099099/The-New-Adventures-of-Sherlock-Holmes-by-Martin-H-Greenberg.pdf
    • http://loaminoo.linkpc.net/4099092096092094/The-Further-Adventures-of-Sherlock-Holmes-The-Web-Weaver-by-Sam-Siciliano.pdf
    • http://loaminoo.linkpc.net/4096095093093098/The-Lost-Adventures-of-Sherlock-Holmes-by-Ken-Greenwald.pdf
    • http://loaminoo.linkpc.net/7092099093090/The-Adventures-Of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/5098091094091/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/9092098099090090/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2093093095099096/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1090092094093090095/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/7095094097091/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1091095091096096097/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/7094093098090096/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/5092094094095094/The-Adventures-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/7095093098095097/A-Paris-Year-My-Day-to-Day-Adventures-in-the-Most-