Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9acf0bfe480290e…

MALICIOUS

PDF

16.9 KB Created: 2019-05-02 03:28:10 +01:00 Authoring application: mPDF 5.7
MD5: 7951f5c353eeeec092cdc7cb85e373b5 SHA-1: d49f605b8d9e507dd072f0080c69d93cb411954d SHA-256: a9acf0bfe480290e816a750494f5d61a7e77115c25e05c9e897c96ec709bbb61
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a potential for SEO manipulation or a link farm designed to redirect users to malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the direct user-facing lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090092092091092/Amanda-in-Alberta-The-Writing-on-the-Stone-Amanda-Travels-4-by-Darlene-Foster.pdf
    • http://loaminoo.linkpc.net/4095094097093095/Amanda-in-Alberta-The-Writing-on-the-Stone-by-Darlene-Foster.pdf
    • http://loaminoo.linkpc.net/4090092092091097/Amanda-in-Arabia-The-Perfume-Flask-by-Darlene-Foster.pdf
    • http://loaminoo.linkpc.net/3090095099091/Chasing-Amanda-by-Melissa-Foster.pdf
    • http://loaminoo.linkpc.net/7093095090090090/Shattered-The-Amanda-Project-3-by-Amanda-Valentino.pdf
    • http://loaminoo.linkpc.net/2090092092098097/Love-Lies-amp-Mystery-Come-Back-to-Me-Chasing-Amanda-Megan-s-Way-by-Melissa-Foster.pdf
    • http://loaminoo.linkpc.net/2093094091099093/The-Adventures-of-Cole-and-Perry-by-Amanda-C-Stone.pdf
    • http://loaminoo.linkpc.net/1096092094092091/Amanda-Lester-and-the-Orange-Crystal-Crisis-Amanda-Lester-Detective-2-by-Paula-Berinstein.pdf
    • http://loaminoo.linkpc.net/9092091099091097/Amanda-Seyfried-173-Success-Facts---Everything-you-need-to-know-about-Amanda-Seyfried-by-Jimmy-Barnett.pdf
    • http://loaminoo.linkpc.net/9092091099091090/Amanda-Seyfried-173-Success-Facts---Everything-You-Need-to-Know-about-Amanda-Seyfried-by-Jimmy-Barnett.pdf
    • http://loaminoo.linkpc.net/9092091098090097/The-Amanda-Seyfried-Handbook---Everything-You-Need-to-Know-about-Amanda-Seyfried-by-Antonio-Serrano.pdf
    • http://loaminoo.linkpc.net/4094093097099091/DC-Comics-The-Sequential-Art-of-Amanda-Conner-by-Amanda-Conner.pdf
    • http://loaminoo.linkpc.net/1099098096096096/Princess-for-a-Summer-An-Amanda-Clarke-Novel-by-Amanda-Clarke.pdf
    • http://loaminoo.linkpc.net/8092091093090092/Travels-in-Persia-1627-1629-by-Thomas-Herbert-Foster.pdf
    • http://loaminoo.linkpc.net/7096095090092/I-d-Like-by-Amanda-Michalopoulou.pdf
    • http://loaminoo.linkpc.net/4098095098094/Amanda-by-Kay-Hooper.pdf
    • http://loaminoo.linkpc.net/1097095090098094/Heir-to-the-Sky-by-Amanda-Sun.pdf
    • http://loaminoo.linkpc.net/5090090098090094/Amanda-by-Kay-Hooper.pdf
    • http://loaminoo.linkpc.net/1097093099092096/Always-by-Amanda-Weaver.pdf
    • http://loaminoo.linkpc.net/2099095099093097/Something-More-by-Amanda-Young.pdf
    • http://loaminoo.linkpc.net/9092091099091097/Amanda-Seyfried-173-Success-Facts---Everything-you-need-to-know-about-Amanda-Seyfried-by-J