Malicious PDF — malware analysis report

Static analysis result for SHA-256 97ca3bb5f6e50434…

MALICIOUS

PDF

12.8 KB Created: 2019-04-30 04:34:23 +01:00 Authoring application: mPDF 5.7
MD5: 86b2eeda31723e6ad2c1b3094b3be847 SHA-1: 36e37d586fc9b6bb7d45a952de2dd5e971462151 SHA-256: 97ca3bb5f6e50434f59152dbca8e9ea86731332e236170bc7df4414c19b71e7a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to serve as a lure for phishing attacks. The PDF_SEO_LINK_FARM heuristic firing strongly supports this assessment. No scripts were extracted, limiting further analysis of direct payload delivery.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091092091091094/Thumbelina-Tiny-Runaway-Bride-by-Barbara-Ensor.pdf
    • http://loaminoo.linkpc.net/9097097090095098/Steven-Ehrlich-Houses-by-Steven-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096098099098/The-Edict-by-Max-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096099090090/The-Cult-by-Max-Ehrlich.pdf
    • http://loaminoo.linkpc.net/3092099090098094/The-Edict-by-Max-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9098094099098/The-Snow-Queen-by-Amy-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1097094096098/The-Drowning-by-Jack-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096099090094/Grant-Speaks-by-E-V-Ehrlich.pdf
    • http://loaminoo.linkpc.net/2096095092090098/Nest-by-Esther-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096098091090/Amo-Amas-Amat-and-More-by-Eugene-Ehrlich.pdf
    • http://loaminoo.linkpc.net/2090091092092092/Heart-Mountain-by-Gretel-Ehrlich.pdf
    • http://loaminoo.linkpc.net/2097098095098/Parents-in-the-Pigpen-Pigs-in-the-Tub-by-Amy-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096097096097/Miriam-s-Kitchen-by-Elizabeth-Ehrlich.pdf
    • http://loaminoo.linkpc.net/2092095099098096/The-Population-Bomb-by-Paul-R-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1098097093096095/The-Reincarnation-of-Peter-Proud-by-Max-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097097090096097/The-Dreams-of-Santiago-Ram-n-Y-Cajal-by-Benjamin-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096098091094/The-Future-of-Ice-A-Journey-Into-Cold-by-Gretel-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096099096095/Medical-Terminology-For-Health-Professions-by-Ann-B-Ehrlich.pdf
    • http://loaminoo.linkpc.net/9097096098099099/When-I-Was-Your-Age-Volumes-I-and-II-Original-Stories-About-Growing-Up-by-Amy-Ehrlich.pdf
    • http://loaminoo.linkpc.net/4091096099095094/The-Solace-of-Open-Spaces-by-Gretel-Ehrlich.pdf
    • http://loaminoo.linkpc.net/1098097093096095/The-R