Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa619ffb80b6448e…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 19:42:19 +01:00 Authoring application: mPDF 5.7
MD5: 76c843cd8431f1246a23e4ae381df046 SHA-1: 735663e750ce5f89109930141df9393b6f67f8fb SHA-256: aa619ffb80b6448eac37d9b85cb2f6ad50e68bf11a2b5811b6636f1615d3836f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the extracted URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099096097090092/Tempt-Me-Cowboy-75th-Copper-Mountain-Rodeo-1-The-Montana-Millionaires-1-by-Megan-Crane.pdf
    • http://loaminoo.linkpc.net/1090099097096/Take-Me-Cowboy-Love-on-Chance-Avenue-1-75th-Copper-Mountain-Rodeo-4-by-Jane-Porter.pdf
    • http://loaminoo.linkpc.net/1091098098096097091/Catch-Me-Cowboy-The-78th-Copper-Mountain-Rodeo-1-Marvells-of-Montana-3-by-Jeannie-Watt.pdf
    • http://loaminoo.linkpc.net/2099096097093095/A-Cowboy-For-Christmas-Copper-Mountain-Christmas-1-The-Scott-Brothers-of-Montana-1-by-Katherine-Garbera.pdf
    • http://loaminoo.linkpc.net/2099096097090090/A-Copper-Mountain-Christmas-Copper-Mountain-Christmas-1-2-4-by-Jane-Porter.pdf
    • http://loaminoo.linkpc.net/2093093099091094/You-Don-t-Have-to-Be-a-Star-Once-Upon-a-Cowboy-Montana-Fire-0-5-Cowboy-Fairytales-1-by-Susan-May-Warren.pdf
    • http://loaminoo.linkpc.net/4091092090097098/Crushing-on-the-Cowboy-Rodeo-Dreamers-1-by-Sarah-M-Anderson.pdf
    • http://loaminoo.linkpc.net/1099095091098098/Opportunity-Montana-Big-Copper-Bad-Water-and-the-Burial-of-an-American-Landscape-by-Brad-Tyer.pdf
    • http://loaminoo.linkpc.net/1091091098090097092/Once-Upon-a-Cowboy-Copper-Creek-2-by-Stina-Lindenblatt.pdf
    • http://loaminoo.linkpc.net/4099092098097097/Wild-Ride-Cowboy-Copper-Ridge-9-by-Maisey-Yates.pdf
    • http://loaminoo.linkpc.net/4090098092097097/Everyone-Else-s-Girl-by-Megan-Crane.pdf
    • http://loaminoo.linkpc.net/4091098091095/Frenemies-by-Megan-Crane.pdf
    • http://loaminoo.linkpc.net/6097091092091092/Full-Service-Blonde-Copper-Black-Mystery-0-by-Megan-Edwards.pdf
    • http://loaminoo.linkpc.net/2092098097095090/Rodeo-Rebel-Texas-Rodeo-Barons-0-5-by-Donna-Alward.pdf
    • http://loaminoo.linkpc.net/4091096090092096/Cowboy-on-My-Mind-Montana-Strong-1-by-R-C-Ryan.pdf
    • http://loaminoo.linkpc.net/3094098092098097/A-Cowboy-to-Keep-Canadays-of-Montana-4-by-Barbara-Ankrum.pdf
    • http://loaminoo.linkpc.net/2095092095096098/The-Cowboy-and-the-Doctor-The-Gallaghers-of-Montana-4-by-Eve-Gaddy.pdf
    • http://loaminoo.linkpc.net/4091098092093097/Rocky-Mountain-Cowboy-Christmas-Rocky-Mountain-Cowboys-1-by-Katie-Ruggle.pdf
    • http://loaminoo.linkpc.net/3094098092099093/The-Cowboy-Rides-Away-Marvells-of-Montana-4-by-Jeannie-Watt.pdf
    • http://loaminoo.linkpc.net/3094094097094091/Mistletoe-Magic-Bar-V5-Dude-Ranch-2-Copper-Mountain-Christmas-3-by-Melissa-McClone.pdf
    • http://loaminoo.linkpc.net/2093093099091094/You-Don-