Malicious PDF — malware analysis report

Static analysis result for SHA-256 a44487ab3359707e…

MALICIOUS

PDF

19.2 KB Created: 2019-04-30 05:06:38 +01:00 Authoring application: mPDF 5.7
MD5: 5e4ab73ed879593392fa97afaec3764e SHA-1: d24c2c82fae76922a4a9a5520d1d0daee7ab7dd7 SHA-256: a44487ab3359707ee715c6bd35421d2236e5e016594c738801200e23152c497a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating a large number of embedded external links. While the extracted URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a potential for distributing malicious content or for SEO manipulation. The document body is heavily corrupted, preventing analysis of its intended purpose. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5095095095090094/Eugenie-Clark-by-Ronald-A-Reis.pdf
    • http://loaminoo.linkpc.net/7092093092098092/Electronic-Project-Design-and-Fabrication-by-Ronald-A-Reis.pdf
    • http://loaminoo.linkpc.net/5095095094097098/Shark-Lady-The-True-Story-of-How-Eugenie-Clark-Became-the-Ocean-s-Most-Fearless-Scientist-by-Jess-Keating.pdf
    • http://loaminoo.linkpc.net/5095095095096092/Memoirs-of-Eugenie-Schumann-by-Eugenie-Schumann.pdf
    • http://loaminoo.linkpc.net/2099094093094097/Slightly-Foxed----but-Still-Desirable-Ronald-Searle-s-Wicked-World-of-Book-Collecting-by-Ronald-Searle.pdf
    • http://loaminoo.linkpc.net/4092090097099092/The-Notes-Ronald-Reagan-s-Private-Collection-of-Stories-and-Wisdom-by-Ronald-Reagan.pdf
    • http://loaminoo.linkpc.net/2096097096096090/Infinite-Blue-by-Natalina-Reis.pdf
    • http://loaminoo.linkpc.net/1091090090094095096/Graz-im-Dunkeln-by-Robert-Reis.pdf
    • http://loaminoo.linkpc.net/1090099095096093091/Een-reis-om-de-wereld-in-45-kip--en-kalkoengerechten-by-Anneke-Ammerlaan.pdf
    • http://loaminoo.linkpc.net/3097093094097/The-Year-of-the-Death-of-Ricardo-Reis-by-Jos-Saramago.pdf
    • http://loaminoo.linkpc.net/1090096096090096095/Der-Spieltrieb-in-Den-Sthetischen-Briefen-Friedrich-Schillers-by-Marcus-Rei-.pdf
    • http://loaminoo.linkpc.net/2095091095090090/De-wonderbaarlijke-reis-van-de-fakir-die-vastzat-in-een-IKEA-kast-by-Romain-Pu-rtolas.pdf
    • http://loaminoo.linkpc.net/2092094097097090/Father-Son-and-Constitution-How-Justice-Tom-Clark-and-Attorney-General-Ramsey-Clark-Shaped-American-Democracy-by-Alexander-Wohl.pdf
    • http://loaminoo.linkpc.net/6098091099091095/The-Classic-Clark-Collection-by-Mary-Higgins-Clark.pdf
    • http://loaminoo.linkpc.net/1091091095099094094/Mensen-van-de-reis-woonwagenbewoners-en-zigeuners-in-Nederland-1868-1995-by-Annemarie-Cottaar.pdf
    • http://loaminoo.linkpc.net/5095095095097098/A-Difficult-Day-by-Eugenie-Fernandes.pdf
    • http://loaminoo.linkpc.net/1091099097090091097/De-verdwenen-prinsessen-of-Milo-s-fantastische-reis-door-het-land-van-letters-en-cijfers-by-Norton-Juster.pdf
    • http://loaminoo.linkpc.net/3092092099094095/Ronald-Reagan-an-American-Hero-by-Ronald-Reagan.pdf
    • http://loaminoo.linkpc.net/5095095094097097/Jenny-s-Surprise-Summer-by-Eugenie.pdf
    • http://loaminoo.linkpc.net/6091094090097096/Little-Robinson-Crusoe-of-Paris-by-Eug-nie-Foa.pdf