Malicious PDF — malware analysis report

Static analysis result for SHA-256 c11a741ccf597fd2…

MALICIOUS

PDF

15.4 KB Created: 2019-05-02 19:32:09 +01:00 Authoring application: mPDF 5.7
MD5: 3c0840fa1368b1fca8876164993eb940 SHA-1: 6efd7f3a7ec449f13651b30dc4e384f012a73fe5 SHA-256: c11a741ccf597fd25ccaabcaf5ab4bf68cf9ea5409fb10446884f221ea49ced2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The heuristic PDF_SEO_LINK_FARM indicates a mass external PDF link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098097095096096/Shotgun-Bride-McKettricks-2-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/3090093094095098/Secondhand-Bride-McKettricks-3-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1096098094090093/The-McKettrick-Way-McKettricks-9-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1095092097099096/Tate-McKettricks-11-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/3097094096091090/A-Lawman-s-Christmas-McKettricks-14-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1094093097096097/McKettrick-s-Heart-McKettricks-8-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1096098091099090/McKettrick-s-Choice-McKettricks-4-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1094093097093099/McKettrick-s-Pride-McKettricks-7-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1094094090092096/Never-Look-Back-Look-Trilogy-2-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1091094098092094092/Winter-in-Stone-Creek-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/9095096094099097/My-Darling-Melissa-Corbins-4-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/2095093097092/The-Rustler-Stone-Creek-3-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1092099096090/Emma-And-The-Outlaw-Orphan-Train-2-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/1092090093090/I-ll-Be-Home-for-Christmas-Bullet-Catcher-2-5-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/6091097096092097/Forever-a-Hero-The-Carsons-of-Mustang-Creek-3-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/9096094095095096/Ein-Cowboy-zum-Verlieben-In-einer-z-rtlichen-Winternacht-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/2093094095093091/A-Creed-In-Stone-Creek-Montana-Creeds-5-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/9096094095096090/H-r-auf-die-Stimme-deines-Herzens-In-einer-z-rtlichen-Winternacht-by-Linda-Lael-Miller.pdf
    • http://loaminoo.linkpc.net/9091094096096093/Tactical-Shotgun-The-Best-Techniques-and-Tactics-for-Employing-the-Shotgun-in-Personal-Combat-by-Gabriel-Suarez.pdf
    • http://loaminoo.linkpc.net/3092099096099098/Hunter-s-Bride-by-Linda-Barlow.pdf