Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc0334863eba6e22…

MALICIOUS

PDF

19.9 KB Created: 2019-05-04 14:07:19 +01:00 Authoring application: mPDF 5.7
MD5: 705e387cbae15051fde5b5d7ce087058 SHA-1: cf4b0ff2611d071be48945b76b315f9c1eb18657 SHA-256: bc0334863eba6e228613312cd1eab7c886ec5cfb2f1984ed217ba24920f6cd7f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating a large number of embedded external links. While the document body is unreadable, the presence of numerous links to external PDFs, many with numeric slugs, suggests a tactic to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample. The primary IOCs are the URLs associated with the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093094095097096/In-All-Directions-by-James-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094097090093/Rnarodne-Srpske-Pjresme-Serbian-Poular-Poetry-Tr-by-J-Bowring-by-John-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094097090091/Autobiographical-Recollections-of-Sir-John-Bowring-With-a-Brief-Memoir-by-Lewin-B-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094092098091/Autobiographical-Recollections-of-Sir-John-Bowring-Volume-1-by-John-Bowring.pdf
    • http://loaminoo.linkpc.net/5096098092090098/Find-Momo-Coast-to-Coast-A-Photography-Book-by-Andrew-Knapp.pdf
    • http://loaminoo.linkpc.net/4093097092095095/rare-visions-and-roadside-revelations-coast-to-coast-travel-o-pedia-by-Randy-Mason.pdf
    • http://loaminoo.linkpc.net/1091093094091090093/Autobiographical-recollections-of-Sir-John-Bowring-by-Sir-John-Bowring.pdf
    • http://loaminoo.linkpc.net/8094096098095090/Chronicling-the-West-for-Harper-s-Coast-to-Coast-with-Frenzeny-Tavernier-in-1873-1874-by-Claudine-Chalmers.pdf
    • http://loaminoo.linkpc.net/4098099096090091/Roadfood-The-Coast-to-Coast-Guide-to-800-of-the-Best-Barbecue-Joints-Lobster-Shacks-Ice-Cream-Parlors-Highway-Diners-and-Much-Much-More-by-Jane-Stern.pdf
    • http://loaminoo.linkpc.net/2099094091097097/From-Approximately-Coast-to-Coast-It-s-the-Bob-and-Ray-Show-by-Bob-Elliott.pdf
    • http://loaminoo.linkpc.net/3094092098098090/American-Murder-Houses-A-Coast-to-Coast-Tour-of-the-Most-Notorious-Houses-of-Homicide-by-Steve-Lehto.pdf
    • http://loaminoo.linkpc.net/1090097095096097098/The-Wonderful-Ride-Being-the-True-Journal-of-Mr-George-T-Loher-Who-in-1895-Cycled-from-Coast-to-Coast-on-His-Yellow-Fellow-Wheel-by-George-T-Loher.pdf
    • http://loaminoo.linkpc.net/4093098091096095/The-10-Best-of-Everything-National-Parks-800-Top-Picks-From-Parks-Coast-to-Coast-by-National-Geographic-Society.pdf
    • http://loaminoo.linkpc.net/1091093094090099098/How-to-Hunt-by-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094095097091/The-Little-Bad-Wolf-by-Sam-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094090099099/The-Animals-Come-First-by-Mary-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094095098094/Vet-in-a-Quandary-by-Mary-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093093099097097/Destiny-s-Rift-Broken-Well-2-by-Sam-Bowring.pdf
    • http://loaminoo.linkpc.net/1091093094090099095/The-Zoo-of-Magical-and-Mythological-Creatures-by-Sam-Bowring.pdf
    • http://loaminoo.linkpc.net/6097094091096092/The-Poems-of-Goethe-by-Edgar-Alfred-Bowring.pdf
    • http://loaminoo.linkpc.net/8094096098095090/Chronicling-the-West-for-Harper-s-Coast-to-Coast-with-Frenzeny-Tavernier-in-1