Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a3e2fe7df03da61…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 18:40:09 +01:00 Authoring application: mPDF 5.7
MD5: 88f266ab64778fcffb68b4647aa21114 SHA-1: f50367e0da8b4f4d99a0b7d76ed9f3c2cbbca626 SHA-256: 8a3e2fe7df03da6100b7dd6246b60a02eb36ef997318e8aa132ccd00ee39c90f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a potential SEO manipulation or content distribution scheme. No scripts were extracted from this sample. The attack pattern is inferred from the link farm and the embedded URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5090093094094098/The-Fallen-Angels-Trilogy-Fallen-Angels-1-3-by-Zoey-Marcel.pdf
    • http://loaminoo.linkpc.net/1091099097093095092/Set-the-Night-on-Fire-by-Connie-Dial.pdf
    • http://loaminoo.linkpc.net/2097091097094090/Angels-are-Real-Angels-Exist-Proof-that-Angels-are-to-help-us-Real-stories-of-Angels-encounters-Ordinary-people-saved-by-Angels-Guardian-Angels-and-Archangels-Angels-are-Real-Angels-Exist-2-by-Tessy-Rawlins.pdf
    • http://loaminoo.linkpc.net/3096094094090094/Rapture-The-Fallen-Angels-4-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/1098099093096091/Envy-Fallen-Angels-3-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/1093091097096096/Crave-Fallen-Angels-2-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/4095094098094/Immortal-Fallen-Angels-6-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/2099098098090098/Immortal-Fallen-Angels-6-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/1091098093093/Covet-Fallen-Angels-1-by-J-R-Ward.pdf
    • http://loaminoo.linkpc.net/9094098090090095/Asa-Fallen-Angels-3-by-Alisa-Woods.pdf
    • http://loaminoo.linkpc.net/4090097097090096/Fallen-Angels-by-Tara-Hyland.pdf
    • http://loaminoo.linkpc.net/2098096098096099/Finally-Fallen-The-Dark-Angels-3-by-Z-Allora.pdf
    • http://loaminoo.linkpc.net/2098099097090/City-of-Fallen-Angels-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2094093097092092/The-Trial-of-Fallen-Angels-by-James-Kimmel-Jr-.pdf
    • http://loaminoo.linkpc.net/7095093098092094/Fallen-Angels-of-Vengence-by-Nathan-Brown.pdf
    • http://loaminoo.linkpc.net/1097092096092097/Angel-Fire-Fallen-Angels-1-by-Valmore-Daniels.pdf
    • http://loaminoo.linkpc.net/3096091091093093/River-of-Fire-Fallen-Angels-6-by-Mary-Jo-Putney.pdf
    • http://loaminoo.linkpc.net/1092096096091/One-Perfect-Rose-Fallen-Angels-7-by-Mary-Jo-Putney.pdf
    • http://loaminoo.linkpc.net/2090094095096090/Constantine-The-Brotherhood-of-Fallen-Angels-4-by-Heather-Grothaus.pdf
    • http://loaminoo.linkpc.net/3092099096090095/Eli-Warriors-For-The-Light-Fallen-Angels-1-by-Karen-Michelle-Nutt.pdf