Malicious PDF — malware analysis report

Static analysis result for SHA-256 c59c2ce409396549…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 02:03:57 +01:00 Authoring application: mPDF 5.7
MD5: 7eddbbcddd6a70a66c1ea37b3a7367a6 SHA-1: 4023cf61cdd199e103595297367035b8c00a0295 SHA-256: c59c2ce40939654942c4b7997e3fd35dd3e50eb1bbcbcbe4207ae833cce092de
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with numerous embedded URLs pointing to external PDF documents. The document body is heavily obfuscated and unreadable, but the presence of a link farm suggests a potential attempt to manipulate search engine results or distribute malicious content. No scripts were extracted from this sample. The primary IOCs are the URLs associated with the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097092093095099/Rats-Alley-by-auburn.pdf
    • http://loaminoo.linkpc.net/6098093090096092/About-Indian-Birds-Including-Birds-of-Nepal-Sri-Lanka-Bhutan-Pakistan-amp-Bangladesh-by-S-lim-Ali.pdf
    • http://loaminoo.linkpc.net/6091092097099094/Coastal-Birds-A-Guide-To-Birds-Of-Maine-s-Beautiful-Coastline-by-DeLorme-Mapping-Company.pdf
    • http://loaminoo.linkpc.net/5094090090096097/Fly-High-With-Birds-The-Best-Book-Guide-On-Bird-Watching-Including-All-The-Things-You-Need-To-Know-About-Birding-Including-Bird-Watching-Scopes-The-Different-Birds-Bird-Feeders-and-Backyard-Birding-Why-Watch-Birds-And-Where-To-Find-Them-For-A-Rewardin-by-Mains.pdf
    • http://loaminoo.linkpc.net/5091098095099099/Auburn-Ride-The-Delarosa-Series-Book-1-by-David-Stever.pdf
    • http://loaminoo.linkpc.net/8093096094093091/Dancing-and-Dancers-of-Today-The-Modern-Revival-of-Dancing-as-an-Art-by-Caroline-Caffin.pdf
    • http://loaminoo.linkpc.net/8093096094093094/Dancing-and-Dancers-of-Today-The-Modern-Revival-of-Dancing-as-an-Art-by-Caroline-Caffin.pdf
    • http://loaminoo.linkpc.net/9093097092090/Wind-in-the-Grasses-Dancing-Dancing-the-Dream-1-by-Terrie-McClay.pdf
    • http://loaminoo.linkpc.net/4095095091099090/No-Dancing-No-Acts-of-Dancing-by-Phyllis-Janik.pdf
    • http://loaminoo.linkpc.net/3092096096094090/Dancing-with-Demons-Dancing-2-by-Andrea-Heltsley.pdf
    • http://loaminoo.linkpc.net/3090090090097094/Little-Birds-by-Ana-s-Nin.pdf
    • http://loaminoo.linkpc.net/9092098091092/Birds-by-Kevin-Henkes.pdf
    • http://loaminoo.linkpc.net/5095092095097/Ten-Birds-by-Cyb-le-Young.pdf
    • http://loaminoo.linkpc.net/1090096099095096090/Birds-Eat-and-Eat-and-Eat-by-Roma-Gans.pdf
    • http://loaminoo.linkpc.net/9096097099/The-Someday-Birds-by-Sally-J-Pla.pdf
    • http://loaminoo.linkpc.net/1093097099093097/The-Birds-by-Daphne-du-Maurier.pdf
    • http://loaminoo.linkpc.net/1097090096094099/The-Birds-by-Daphne-du-Maurier.pdf
    • http://loaminoo.linkpc.net/7095093095/Birds-of-Wonder-by-Cynthia-Robinson.pdf
    • http://loaminoo.linkpc.net/3090098090090095/Winter-Birds-by-Jim-Grimsley.pdf
    • http://loaminoo.linkpc.net/4090090095090090/The-King-Of-The-Birds-by-Helen-Ward.pdf
    • http://loaminoo.linkpc.net/8093096094093094/Dancing-and-Dancers-of-Today-The-Modern-Revival-of-Dancing-as-a