Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a76390b81ed6c7f…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:07:15 +01:00 Authoring application: mPDF 5.7
MD5: 8f782e43ca7373146ceed8628a6c67a3 SHA-1: 1d3bbf6fe2307e69169810fe66d9a6f201a0e100 SHA-256: 8a76390b81ed6c7ff39842d80508c96f0a242bbb1702c03c071086192e0aab34
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating a large number of embedded external links. While the extracted URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly to manipulate search engine results or to serve as a lure for further malicious activity. No scripts were extracted from this sample. The attack pattern is inferred from the link farm heuristic.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095099092092094/A-History-of-Railroad-Accidents-Safety-Precautions-and-Operating-Practices-by-Robert-B-Shaw.pdf
    • http://loaminoo.linkpc.net/8095099091095095/Aromatherapy-Oils-Safety-Precautions-by-Miriam-Kinai.pdf
    • http://loaminoo.linkpc.net/8095099092090091/Laboratory-Techniques-Safety-Precautions-by-H-Anthony-Neidig.pdf
    • http://loaminoo.linkpc.net/8095099091095091/Taking-Precautions-An-Intimate-History-of-Birth-Control-by-Shyama-Perera.pdf
    • http://loaminoo.linkpc.net/8098096094092092/Laboratory-Safety-for-Chemistry-Students-by-Robert-H-Hill.pdf
    • http://loaminoo.linkpc.net/8098096093099099/Laboratory-Safety-for-Chemistry-Students-by-Robert-H-Hill-Jr-.pdf
    • http://loaminoo.linkpc.net/7096095097091090/Five-Practices---Extravagant-Generosity-by-Robert-C-Schnase.pdf
    • http://loaminoo.linkpc.net/8095097097099096/Maligne-Lake-Safety-Book-The-Essential-Lake-Safety-Guide-for-Children-by-Jobe-Leonard.pdf
    • http://loaminoo.linkpc.net/5091096098093097/The-Lesbian-S-M-Safety-Manual-Basic-Health-and-Safety-for-Woman-To-Woman-S-M-by-Patrick-Califia-Rice.pdf
    • http://loaminoo.linkpc.net/5094095092093093/Fighter-Combat-Tactics-and-Maneuvering-by-Robert-L-Shaw.pdf
    • http://loaminoo.linkpc.net/3099095094095/No-Safety-in-Numbers-No-Safety-in-Numbers-1-by-Dayna-Lorentz.pdf
    • http://loaminoo.linkpc.net/2090096099095091/Standard-Operating-Procedure-by-Philip-Gourevitch.pdf
    • http://loaminoo.linkpc.net/1094092093091090/Hand-Made-Hand-Played-The-Art-Craft-of-Contemporary-Guitars-by-Robert-Shaw.pdf
    • http://loaminoo.linkpc.net/5099094099095096/Operating-Systems-Concepts-and-Design-by-Milan-Milenkovic.pdf
    • http://loaminoo.linkpc.net/4093092094094/Operating-Instructions-A-Journal-of-My-Son-s-First-Year-by-Anne-Lamott.pdf
    • http://loaminoo.linkpc.net/5090096092098092/Accidents-by-Yael-Hedaya.pdf
    • http://loaminoo.linkpc.net/7099091099092098/Recent-developments-in-the-study-of-business-and-economic-history-Essays-in-memory-of-Herman-E-Krooss-Research-in-Economic-History-Supplement-1-by-Robert-E-Gallman.pdf
    • http://loaminoo.linkpc.net/1091099093096098093/Happy-Accidents-by-Jane-Lynch.pdf
    • http://loaminoo.linkpc.net/4092093097099094/Accidents-of-Nature-by-Harriet-McBryde-Johnson.pdf
    • http://loaminoo.linkpc.net/8095099091091093/Air-Raid-Precautions-by-Campbell-McCutcheon.pdf
    • http://loaminoo.linkpc.net/5091096098093097/The-Lesbian-S-M-Safety-Manual-Basic-He