Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e5393958545abaf…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 02:05:01 +01:00 Authoring application: mPDF 5.7
MD5: 93c982029b0be9e957083bfe5ad9c2d1 SHA-1: ea3d17d0a876d4ad920841cda343f178c5bf2e93 SHA-256: 9e5393958545abafdd1dd234a62fdba74b938bec7078b9d33347bb8d9760a881
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book-related PDFs. While the URLs themselves are marked as benign, the sheer volume and the ClamAV detection as Pdf.Dropper.Agent-7154256-0 indicate a malicious intent, likely to manipulate search engine rankings or redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7154256-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7154256-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098095092096092/Ulysses-by-James-Joyce-Illustrated-Delphi-Parts-Edition-James-Joyce-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/5095091090093098/Ulysses-By-James-Joyce-Illustrated---Original-amp-Unabridged-Free-Audiobook-Inside-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/5097092091090091/ULYSSES---JAMES-JOYCE-WITH-NOTES-BIOGRAPHY-ILLUSTRATED-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/7094096095095094/Ulysses-20th-Century-Fiction-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/1090094091098099091/ULYSSES-Optimized-for-ebook-Illustrated-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/1091095094094099099/Ulysses-With-Linked-Table-of-Contents-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/8090092099098098/Ulysses-Color-Illustrated-Formatted-for-E-Readers-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/8092092090090/The-Most-Dangerous-Book-The-Battle-for-James-Joyce-s-Ulysses-by-Kevin-Birmingham.pdf
    • http://loaminoo.linkpc.net/2098091097095099/The-Most-Dangerous-Book-The-Battle-for-James-Joyce-s-Ulysses-by-Kevin-Birmingham.pdf
    • http://loaminoo.linkpc.net/5094099090093099/Ulysses-Annotated-Characters-Analysis-Themes-Motifs-Symbols-amp-Study-Questions-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/7095090096096091/Dubliners-By-James-Joyce-Illustrated-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/1091099098097090092/James-Joyces-Ulysses-in-Vier-Deutschen-Uebersetzungen-Samt-Einem-Ausblick-Auf-Die-Niederlaendische-Uebersetzung-by-Heinrich-Versteegen.pdf
    • http://loaminoo.linkpc.net/7095098097090094/Ulisse-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/6091097092098/The-Dead-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/6098090094098/Dubliners-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/6096092098095097/Dubliners-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/4096095090096092/Dubliners-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/6096095094091/Eveline-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/3093092098094098/A-Mother-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/6091099092091095/Dubliners-by-James-Joyce.pdf
    • http://loaminoo.linkpc.net/8092092090090/The-Most-Dangerous-Book-The-Battle-for-James-Joyce-s-Ulysses-by-Kevin-Birmingha