Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7fc9277e32bb61a…

MALICIOUS

PDF

23.1 KB Created: 2019-04-30 06:28:14 +01:00 Authoring application: mPDF 5.7
MD5: 5a9f76237af7629bbb9a8e956633294a SHA-1: 77fac6c92f943c16062300c51dfb0aa2ac627eb7 SHA-256: c7fc9277e32bb61a65f004a0e66fe11f9945a73a601802ef437cc053c818b4cf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential for malicious redirection or SEO abuse. No scripts were extracted from this sample, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094092090095091/A-Companion-to-Middle-High-German-Literature-to-the-14th-Century-by-Francis-G-Gentry.pdf
    • http://loaminoo.linkpc.net/6091098099099095/The-Troubadours-A-History-of-Provencal-Life-and-Literature-in-the-Middle-Ages-by-Francis-Hueffer.pdf
    • http://loaminoo.linkpc.net/1097098090098094/The-Norton-Anthology-of-English-Literature-Volume-1-The-Middle-Ages-through-the-Restoration-amp-the-Eighteenth-Century-by-M-H-Abrams.pdf
    • http://loaminoo.linkpc.net/3099095095097098/Tristan-and-Isolde-by-Francis-Gentry.pdf
    • http://loaminoo.linkpc.net/2097094097091098/A-Distant-Mirror-The-Calamitous-14th-Century-by-Barbara-W-Tuchman.pdf
    • http://loaminoo.linkpc.net/3097092096091099/The-Nibelungen-Tradition-An-Encyclopedia-by-Francis-G-Gentry.pdf
    • http://loaminoo.linkpc.net/8097092090090098/The-Third-Horseman-Climate-Change-and-the-Great-Famine-of-the-14th-Century-by-William-Rosen.pdf
    • http://loaminoo.linkpc.net/3099090092094097/The-Broadview-Anthology-of-British-Literature-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-by-Joseph-Laurence-Black.pdf
    • http://loaminoo.linkpc.net/8098090092099099/The-German-Research-Companion-by-Shirley-J-Riemer.pdf
    • http://loaminoo.linkpc.net/4099090094095098/The-Cambridge-Companion-to-Canadian-Literature-by-Eva-Marie-Kr-ller.pdf
    • http://loaminoo.linkpc.net/8091096093094091/History-of-Europe-amp-the-Middle-East-Course-Companion-by-Mariam-Habibi.pdf
    • http://loaminoo.linkpc.net/1090096097090093090/German-Literature-on-the-Go-Volume-2-Der-Schimmelreiter-by-Theodor-Storm.pdf
    • http://loaminoo.linkpc.net/2093092092096093/Lay-Piety-and-Religious-Discipline-in-Middle-English-Literature-by-Nicole-R-Rice.pdf
    • http://loaminoo.linkpc.net/1090093094098097095/German-Literature-on-the-Go-Volume-5-Aus-Dem-Leben-Eines-Taugenichts-by-Joseph-von-Eichendorff.pdf
    • http://loaminoo.linkpc.net/7097090091099094/Cairo-to-Constantinople-Francis-Bedford-s-Photographs-of-the-Middle-East-by-Sophie-Gordon.pdf
    • http://loaminoo.linkpc.net/1091094098098096095/Art-Of-The-Middle-Ages-Translated-From-German-By-Robert-Erich-Wolf-by-HANS-HELMUT-HOFSTATTER.pdf
    • http://loaminoo.linkpc.net/3097091095098092/High-Stakes-by-Dick-Francis.pdf
    • http://loaminoo.linkpc.net/9095097090094096/The-High-Middle-Ages-in-Germany-by-Rolf-Toman.pdf
    • http://loaminoo.linkpc.net/6093092094096099/Tall-Tales-From-The-German-Woods-The-Myth-Of-The-Wannsee-Conference-by-Francis-Dupont.pdf
    • http://loaminoo.linkpc.net/1090097098094093091/Modes-amp-Manners-From-the-Middle-Ages-to-the-End-of-the-Eighteenth-Century-by-Max-Von-Boehn.pdf