Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dbbffba56415a30…

MALICIOUS

PDF

13.2 KB Created: 2019-04-30 03:14:46 +01:00 Authoring application: mPDF 5.7
MD5: 81914da98a42ddd7ba094e01a9c9822e SHA-1: dc799d5250f262f4c41826ed66579eb41be2b22f SHA-256: 9dbbffba56415a30ec064dad3443aea86437c7855d350be86545f2ee8c8b1400
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with numerous embedded URLs pointing to external PDF documents. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the PDF_SEO_LINK_FARM rule suggest a malicious intent, likely to manipulate search engine results or to serve as a distribution point for further malicious content. No scripts were extracted, limiting the ability to determine the exact payload or delivery mechanism.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098095095095096/The-Bone-Flute-by-N-A-Bourke.pdf
    • http://loaminoo.linkpc.net/1095091091091093/Bone-by-Bone-Comparing-Animal-Skeletons-by-Sara-Levine.pdf
    • http://loaminoo.linkpc.net/2094091094091094/Bone-Vol-9-Crown-of-Horns-Bone-9-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/1098094092095099/Bone-Vol-8-Treasure-Hunters-Bone-8-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/1098094092095098/Bone-Vol-9-Crown-of-Horns-Bone-9-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/4093095099091/Bone-Vol-3-Eyes-of-the-Storm-Bone-3-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/4094092094093/Bone-Vol-2-The-Great-Cow-Race-Bone-2-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/7095090097097/What-the-Sky-Knows-by-Nike-Bourke.pdf
    • http://loaminoo.linkpc.net/3095099093096/Bone-Vol-1-Out-from-Boneville-Bone-1-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/6095099095099/Bone-Vol-4-The-Dragonslayer-Bone-4-by-Jeff-Smith.pdf
    • http://loaminoo.linkpc.net/3095094096091091/From-India-with-Love-by-Latika-Bourke.pdf
    • http://loaminoo.linkpc.net/6091095097091096/Maeve-Brennan-Homesick-at-The-New-Yorker-by-Angela-Bourke.pdf
    • http://loaminoo.linkpc.net/6093096091094/Good-bye-Maoriland-The-Songs-and-Sounds-of-New-Zealand-s-Great-War-by-Chris-Bourke.pdf
    • http://loaminoo.linkpc.net/3095092097093090/Maeve-Brennan-Wit-Style-and-Tragedy-An-Irish-Writer-in-New-York-by-Angela-Bourke.pdf
    • http://loaminoo.linkpc.net/1095091092091097/The-Tin-Flute-by-Gabrielle-Roy.pdf
    • http://loaminoo.linkpc.net/6098099097092091/The-Flute-by-Valerie-A-Beauchene.pdf
    • http://loaminoo.linkpc.net/5096093096098099/Joueur-de-fl-te-d-Hamelin-by-Various.pdf
    • http://loaminoo.linkpc.net/1096095093097091/The-Stone-and-the-Flute-by-Hans-Bemmann.pdf
    • http://loaminoo.linkpc.net/8094090090092098/The-Broken-Flute-by-Sunday-Eyitayo-Michael.pdf
    • http://loaminoo.linkpc.net/1090090097091099096/Paganini-24-Caprices-For-Flute-by-Marina-Piccinini.pdf
    • http://loaminoo.linkpc.net/6093096091094/Good-bye-Maoriland-The-Songs-and-Sounds-of-New-Zealand-s