Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b8a6a77592ec8d5…

MALICIOUS

PDF

13.2 KB Created: 2019-04-30 03:15:56 +01:00 Authoring application: mPDF 5.7
MD5: 66538e43aa99cd615f7487a0231f2e99 SHA-1: bea4c8985e0db4352812e8610f599d69e619438e SHA-256: 8b8a6a77592ec8d559bc254c6398da7cca3f6cfd4ea872e9d3b68d278b47628a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. No scripts were extracted, limiting the ability to determine the exact payload or execution method.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094097094096/Touched-by-Sunlight-by-Leslie-D-Stuart.pdf
    • http://loaminoo.linkpc.net/2096098091091090/If-You-are-Lucky-by-Leslie-D-Stuart.pdf
    • http://loaminoo.linkpc.net/2092092095092097/Roses-in-Winter-by-Leslie-D-Stuart.pdf
    • http://loaminoo.linkpc.net/1099098096094090/Touched-Touched-1-by-Elisa-S-Amore.pdf
    • http://loaminoo.linkpc.net/1095090090091092/The-Royal-Road-to-Fotheringhay-Stuart-Saga-1-Mary-Stuart-1-by-Jean-Plaidy.pdf
    • http://loaminoo.linkpc.net/3092093094095094/Sunlight-by-Jill-Myles.pdf
    • http://loaminoo.linkpc.net/2096097095095093/The-Loss-of-Sunlight-by-Lia-Black.pdf
    • http://loaminoo.linkpc.net/2091098094097091/Sunlight-and-Shadow-by-Cameron-Dokey.pdf
    • http://loaminoo.linkpc.net/1091097095094091093/Dangerous-Sunlight-by-John-Bude.pdf
    • http://loaminoo.linkpc.net/1099095097092/Awakening-to-Sunlight-by-Lindsey-Stone.pdf
    • http://loaminoo.linkpc.net/7099092093/Women-in-Sunlight-by-Frances-Mayes.pdf
    • http://loaminoo.linkpc.net/3093091097092098/Cloudbreakers-Legend-of-the-Sunlight-Prince-by-K-J-Moore.pdf
    • http://loaminoo.linkpc.net/5096098093096092/Action-of-sunlight-on-glass-by-Thomas-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093096095/The-Action-of-Sunlight-on-Glass-by-Thomas-Gaffield.pdf
    • http://loaminoo.linkpc.net/1090091097095090096/Capturing-Sunlight-The-Rune-Stone-Trilogy-2-by-Anne-Haley.pdf
    • http://loaminoo.linkpc.net/1098097098091093/Capturing-Sunlight-The-Rune-Stone-Trilogy-2-by-Anne-Haley.pdf
    • http://loaminoo.linkpc.net/8091094099098092/Kohaku-to-Ao-no-Shizuku-Amber-Sunlight-Lit-Up-the-Jade-Dewdrops-by-Akiho-Kousaka.pdf
    • http://loaminoo.linkpc.net/4096098099093095/Kissed-Belle-Sunlight-and-Shadow-Winter-s-Child-by-Cameron-Dokey.pdf
    • http://loaminoo.linkpc.net/3090090093094095/Leslie-Nielsen-The-Naked-Truth-by-Leslie-Nielsen.pdf
    • http://loaminoo.linkpc.net/7099098090097091/Leslie-Peltier-s-guide-to-the-stars-by-Leslie-C-Peltier.pdf
    • http://loaminoo.linkpc.net/1090091097095090096/Capturing-Sunlight-The-Rune-Stone