Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc2978c57002ea03…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 04:33:06 +01:00 Authoring application: mPDF 5.7
MD5: 5d914f60c21a40eae0c8be3b27988d4c SHA-1: 778e9c3cbd10712ab33fcd416a5093c8370c96c4 SHA-256: bc2978c57002ea03f99fe68bf49f3a5a3dad1d82b8362a53f41c105bcc57b19f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as confirmed benign, the sheer volume and the heuristic's critical severity suggest a malicious intent, likely for SEO manipulation or to serve as a lure for further malicious activity. The ClamAV detection as Pdf.Dropper.Agent-7386654-0 further supports its malicious nature. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7386654-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7386654-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090090092093/A-Body-to-Dye-For-Stan-Kraychik-Mystery-1-by-Grant-Michaels.pdf
    • http://loaminoo.linkpc.net/1099097097093/Time-to-Check-Out-Stan-Kraychik-Mystery-5-by-Grant-Michaels.pdf
    • http://loaminoo.linkpc.net/1099098098090/Mask-For-A-Diva-Stan-Kraychik-Mystery-4-by-Grant-Michaels.pdf
    • http://loaminoo.linkpc.net/1099099090098/Love-You-to-Death-Stan-Kraychik-Mystery-2-by-Grant-Michaels.pdf
    • http://loaminoo.linkpc.net/2095099092093099/Talking-To-My-Country-by-Stan-Grant.pdf
    • http://loaminoo.linkpc.net/1090095099096096094/Journey-Into-Mystery-86-by-Stan-Lee.pdf
    • http://loaminoo.linkpc.net/2092092093098098/U-S-Grant-The-Civil-War-Years-Grant-Moves-South-and-Grant-Takes-Command-by-Bruce-Catton.pdf
    • http://loaminoo.linkpc.net/1090099096099097099/Stan-Without-Ollie-The-Stan-Laurel-Solo-Films-1917-1927-by-Ted-Okuda.pdf
    • http://loaminoo.linkpc.net/1091099095095091091/The-No-More-Excuses-Guide-to-Yoga-Because-yoga-is-for-Every-body-by-Kara-Leah-Grant.pdf
    • http://loaminoo.linkpc.net/3097093096094095/High-Heels-and-Holidays-Maggie-Kelly-Mystery-5-by-Kasey-Michaels.pdf
    • http://loaminoo.linkpc.net/2096099095094099/Is-Your-Body-Trying-to-Tell-You-Something-Why-It-Is-Wise-to-Listen-to-Your-Body-and-How-Massage-and-Body-Work-Can-Help-by-Carmen-Renee-Berry.pdf
    • http://loaminoo.linkpc.net/4097098094095095/Excelsior-The-Amazing-Life-of-Stan-Lee-by-Stan-Lee.pdf
    • http://loaminoo.linkpc.net/4090096092093095/The-Body-in-the-Goldenrod-A-Catherine-Jewell-Mystery-4-by-Gloria-Alden.pdf
    • http://loaminoo.linkpc.net/6094099099094091/Body-in-the-Woods-Reverend-Annabelle-Dixon-Mystery-2-by-Alison-Golden.pdf
    • http://loaminoo.linkpc.net/1091096094097098/The-Body-on-the-Lido-Deck-A-Toni-Day-Mystery-by-Jane-Bennett-Munro.pdf
    • http://loaminoo.linkpc.net/2096098093096094/Body-on-Baker-Street-A-Sherlock-Holmes-Bookshop-Mystery-2-by-Vicki-Delany.pdf
    • http://loaminoo.linkpc.net/2093099092091099/The-Mirror-Crack-d-A-Caribbean-Mystery-Nemesis-What-Mrs-McGillicuddy-Saw-The-Body-in-the-Library-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/6091095096096091/The-Personal-Memoirs-of-Julia-Dent-Grant-Mrs-Ulysses-S-Grant-by-John-Y-Simon.pdf
    • http://loaminoo.linkpc.net/9099095099093/Good-Stuff-A-Reminiscence-of-My-Father-Cary-Grant-by-Jennifer-Grant.pdf
    • http://loaminoo.linkpc.net/5092091095097097/Personal-Memoirs-of-U-S-Grant-Part-5-by-Ulysses-S-Grant.pdf
    • http://loaminoo.linkpc.net/2096099095094099/Is-Your-Body-Trying-to-Te