Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfb7c199ffbff052…

MALICIOUS

PDF

13.9 KB Created: 2019-04-30 18:39:36 +01:00 Authoring application: mPDF 5.7
MD5: 7167b07e7b979d3a63b7b336b8a58342 SHA-1: 69e1fef420c68b40fd0345915db7d7bd73ccb9db SHA-256: bfb7c199ffbff052f8572639d17a86491621fabe736bb6f2835ec81b034365d7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious sites. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/9091099090093092/Veronica-by-Roger-Duvoisin.pdf
    • http://loaminoo.linkpc.net/1090099099090093096/Petunia-Goes-Wild-by-Paul-Schmid.pdf
    • http://loaminoo.linkpc.net/3093096090099092/Petunia-the-Girl-who-was-NOT-a-Princess-by-M-R-Nelson.pdf
    • http://loaminoo.linkpc.net/2094092095090092/Don-t-Touch-My-Petunia-The-Holloway-Girls-2-by-Tara-Sheets.pdf
    • http://loaminoo.linkpc.net/4095099097094097/All-the-Best-The-Selected-Poems-Of-Roger-Mc-Gough-by-Roger-McGough.pdf
    • http://loaminoo.linkpc.net/4091097099099090/The-Complete-Writings-of-Roger-Williams---Volume-3-Bloudy-Tenent-of-Persecution-by-Roger-Williams.pdf
    • http://loaminoo.linkpc.net/9091094091097/Last-Exit-to-Babylon-The-Collected-Stories-of-Roger-Zelazny-Vol-4-by-Roger-Zelazny.pdf
    • http://loaminoo.linkpc.net/8094094090096090/Roger-Ebert-s-Four-Star-Reviews-1967-2007-by-Roger-Ebert.pdf
    • http://loaminoo.linkpc.net/3090093091098090/Who-Censored-Roger-Rabbit-Roger-Rabbit-1-by-Gary-K-Wolf.pdf
    • http://loaminoo.linkpc.net/9091096094098096/Roger-Ebert-s-Movie-Yearbook-2004-by-Roger-Ebert.pdf
    • http://loaminoo.linkpc.net/9091096094098095/Roger-Ebert-s-Movie-Yearbook-2002-by-Roger-Ebert.pdf
    • http://loaminoo.linkpc.net/5090095093093/Awake-in-the-Dark-The-Best-of-Roger-Ebert-by-Roger-Ebert.pdf
    • http://loaminoo.linkpc.net/3098090096098096/Mr-Mean-by-Roger-Hargreaves.pdf
    • http://loaminoo.linkpc.net/2094092092093094/The-BOX-by-Roger-McKasson.pdf
    • http://loaminoo.linkpc.net/3098090097097090/Mr-Clever-Mr-Men-37-by-Roger-Hargreaves.pdf
    • http://loaminoo.linkpc.net/7090099091095/Roger-and-the-Fox-by-Lavinia-R-Davis.pdf
    • http://loaminoo.linkpc.net/8094096096092091/The-Annick-ABC-by-Roger-Pare.pdf
    • http://loaminoo.linkpc.net/2091094096098090/This-Immortal-by-Roger-Zelazny.pdf
    • http://loaminoo.linkpc.net/3098090097096095/Mr-Grumpy-by-Roger-Hargreaves.pdf
    • http://loaminoo.linkpc.net/3098090096098095/Mr-Funny-by-Roger-Hargreaves.pdf