Malicious PDF — malware analysis report

Static analysis result for SHA-256 909ebc9875c44d99…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:33:40 +01:00 Authoring application: mPDF 5.7
MD5: 8818654269ddb30d80950ac76ffeb978 SHA-1: 2fe72b8047f057f18f5d69365132ac55b6b6a320 SHA-256: 909ebc9875c44d9913fde43cf9eb2f65db891b98e47a16e38c357bdcb317736f
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links resolve to benign content, the sheer volume and the presence of the SE_URGENCY_LURE heuristic suggest a deceptive intent. The document body itself is heavily obfuscated, but it does contain URLs that are likely part of the link farm. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095095095098091/Texas-Destiny-Texas-Glory-Texas-Splendor-Leigh-Brothers-Texas-Trilogy-1-3-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2093090094097090/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2095095093097094/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/8094096094095/A-Rogue-in-Texas-Rogues-in-Texas-1-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2093092099091093/Never-Love-a-Cowboy-Rogues-in-Texas-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/4099090095095099/Last-Chance-Reunion-Texas-Cold-Case-Texas-Lost-and-Found-Chance-Texas-4-by-Linda-Conrad.pdf
    • http://loaminoo.linkpc.net/9090096096091/Texas-Fortunes-Trilogy-Texas-Fortunes-Trilogy-1-3-by-Marcia-Gruver.pdf
    • http://loaminoo.linkpc.net/2090090093094098/Heart-of-Texas-Vol-1-Lonesome-Cowboy-Texas-Two-Step-Heart-of-Texas-1-2-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/2097097093090091/Lassoed-in-Texas-Trilogy-Lassoed-in-Texas-1-3-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/4093091096095093/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/2097097096090099/Texas-Boardinghouse-Brides-Trilogy-Texas-Boardinghouse-Brides-1-3-by-Vickie-McDonough.pdf
    • http://loaminoo.linkpc.net/4097096094095095/A-Match-Made-in-Texas-Deep-in-the-Heart-of-Texas-6-by-Katie-Lane.pdf
    • http://loaminoo.linkpc.net/2095092091092/The-Texas-Renegade-Returns-Texas-Cattleman-s-Club-A-Missing-Mogul-10-by-Charlene-Sands.pdf
    • http://loaminoo.linkpc.net/1091093091094/Tougher-in-Texas-Texas-Rodeo-3-by-Kari-Lynn-Dell.pdf
    • http://loaminoo.linkpc.net/3094098091092097/Reckless-in-Texas-Texas-Rodeo-1-by-Kari-Lynn-Dell.pdf
    • http://loaminoo.linkpc.net/1092092095099098/To-Catch-a-Texas-Star-Texas-Heroes-3-by-Linda-Broday.pdf
    • http://loaminoo.linkpc.net/2098091092093097/Texas-Twist-Texas-Montgomery-Mavericks-4-by-Cynthia-D-39-Alba.pdf
    • http://loaminoo.linkpc.net/1097092093090096/Texas-Two-Step-Whispering-Springs-Texas-1-by-Cynthia-D-39-Alba.pdf
    • http://loaminoo.linkpc.net/2097098092097092/Texas-Hard-Texas-Soul-2-by-Sara-York.pdf
    • http://loaminoo.linkpc.net/1094095095097097/Blame-It-On-Texas-Hotter-In-Texas-2-by-Christie-Craig.pdf
    • http://loaminoo.linkpc.net/2090090093094098/Heart-of