Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1d39480cf76e7fb…

MALICIOUS

PDF

50.4 KB Created: 2019-05-02 17:57:56 +01:00 Authoring application: mPDF 5.7
MD5: 7fc465951ac28f2de2dd465d58c7bb54 SHA-1: afd82e75d37c1d16636e80236e78661332e1914e SHA-256: b1d39480cf76e7fba7a217323f5a23344408615086ea254165616ce910aef20e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, indicating a link farm or redirection scheme. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. While no scripts were extracted, the sheer volume of links points towards an attempt to drive traffic to potentially malicious or deceptive websites. The document body was unreadable, preventing further analysis of its specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8090090091094092/The-Collection-of-United-States-Cents-of-Dr-S-T-Millard-Together-with-the-Collections-of-United-States-and-Pioneer-Gold-and-Silver-Coins-of-Mr-Edward-Heissler-Chicago-and-Other-Properties-To-Be-Sold-at-Auction-Thursday-March-18th-1915-by-B-Max-Mehl.pdf
    • http://loaminoo.linkpc.net/8095092098091096/In-the-United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-United-States-of-America-Appellant-vs-Emery-J-Lesher-Appelle-Transcript-of-Record-Upon-Appeal-from-the-United-States-District-Court-for-the-District-of-Oregon-by-United-States-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/1090091094093093091/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-1912-Vol-5-of-6-Transcript-of-Record-William-F-Kettenbach-and-George-H-Kester-Plaintiffs-in-Error-Vs-The-United-States-of-America-Defendant-in-Error-Pages-1521-to-1916-Inclusive-by-United-States-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/1090091094093094090/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Vol-3-of-6-Transcript-of-Record-William-F-Kettenbach-Geo-H-Kester-and-William-Dwyer-Plaintiffs-in-Error-vs-the-United-States-of-America-Defendant-in-Error-Pages-817-to-1232-Inclusi-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/8095092098091093/United-States-Circuit-Court-of-Appeals-Fo-the-Ninth-Circuit-The-United-States-of-America-Appellant-vs-Komada-and-Co-Appelle-Condensed-Transcript-of-Record-Upon-Appeal-from-the-United-States-Circuit-Court-for-Northern-District-of-California-by-U-S-Court-of-Appeals-Ninth-Circuit.pdf
    • http://loaminoo.linkpc.net/1090092094096090093/United-States-Court-of-Appeals-for-the-Ninth-Circuit-Connell-Brothers-Company-a-Corporation-Plaintiff-in-Error-vs-H-Diederichsen-and-Company-Defendant-in-Error-Transcript-of-Record-Upon-Writ-of-Error-to-the-United-States-Court-for-China-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/4090090099098093/Encyclopedia-of-the-Commemorative-Coins-of-the-United-States-by-Anthony-Swiatek.pdf
    • http://loaminoo.linkpc.net/1090098092097091097/Millard-Fillmore-13th-President-of-the-United-States-by-Heidi-Elston.pdf
    • http://loaminoo.linkpc.net/4095099093096099/Testimony-The-United-States-1885-1915-by-Charles-Renznikoff.pdf
    • http://loaminoo.linkpc.net/4095099094095093/Testimony-The-United-States-1885-1915-Recitative-by-Charles-Reznikoff.pdf
    • http://loaminoo.linkpc.net/8090095090095092/Drogue-Surveys-of-Lake-Currents-Near-Chicago-by-United-States-Environmenta-Agency-Epa-.pdf
    • http://loaminoo.linkpc.net/8095092097099098/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Ngai-Kwan-Ying-Appellant-vs-John-D-Nagle-Commissioner-of-Immigration-Port-of-San-Francisco-California-Appelle-Transcript-of-Record-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/5091098095090099/The-United-States-Navy-200-Years-by-Edward-L-Beach.pdf
    • http://loaminoo.linkpc.net/3090095098096099/Regions-Apart-The-Four-Societies-of-Canada-and-the-United-States-by-Edward-Grabb.pdf
    • http://loaminoo.linkpc.net/8095092098091098/United-States-Court-of-Appeals-for-the-Ninth-Circuit-Vol-1-of-3-Greene-Process-Metal-Company-a-Corporation-Appellant-vs-Washington-Iron-Works-a-Corporation-Appelle-Transcript-of-Record-Pages-1-522-Upon-Appeal-from-the-District-Court-of-the-Uni-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/1095096094099/Riches-Class-and-Power-United-States-Before-the-Civil-War-by-Edward-Pessen.pdf
    • http://loaminoo.linkpc.net/5091098095090090/Shield-and-Sword-The-United-States-Navy-and-the-Persian-Gulf-War-by-Edward-J-Marolda.pdf
    • http://loaminoo.linkpc.net/8095092097099095/In-the-United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Wilson-Western-Sporting-Goods-Co-a-Corporation-Appellant-and-Cross-Appellee-vs-George-E-Barnhart-Cross-Appellant-and-Appelle-by-United-States-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/8095092098090094/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-N-N-S-Matcovich-Appellant-vs-Richard-Nickell-as-Collector-of-Internal-Revenue-for-the-First-District-of-California-Appelle-Transcript-of-Record-Upon-Appeal-from-the-District-Court-of-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://loaminoo.linkpc.net/6096094097099090/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Walter-M-Petitfils-Petitioner-vs-Commissioner-of-Internal-Revenue-Respondent-Transcript-of-Record-Upon-Petition-to-Review-an-Order-of-the-United-States-Board-of-Tax-Appeals-by-U-S-Court-of-Appeals-Ninth-Circuit.pdf
    • http://loaminoo.linkpc.net/1090091094093093091/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-1912-Vol-5-of-6-Transcript-of-Record-William-F-Kettenbach-and-George-H-Kester-Plaintiffs-in-Error-Vs-The-United-States-of-America-Defendant-in-Error-Pages-1521-to-1916-Inclusive-by-United-States-Court-