Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca2080e7ba24e3ec…

MALICIOUS

PDF

22.9 KB Created: 2019-05-02 00:56:11 +01:00 Authoring application: mPDF 5.7
MD5: 6a20828764a8c21ab9db2492d70784b2 SHA-1: 939cfeddc3ea036160b7b6dd3c3467fabad7c0f3 SHA-256: ca2080e7ba24e3ec29b831ed6dd3fa54cd8fea31f2eb00d6d37ce7361d8b6444
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. While no scripts were extracted, the sheer volume of links and their structure indicate a coordinated effort to direct users to potentially harmful resources. The document body was unreadable, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6096096099097094/Quantitative-Value-A-Practitioner-s-Guide-to-Automating-Intelligent-Investment-and-Eliminating-Behavioral-Errors-by-Wesley-R-Gray.pdf
    • http://loaminoo.linkpc.net/5093092095098/Only-Human-Part-Two---Virtus-by-Wesley-Gray.pdf
    • http://loaminoo.linkpc.net/7093090091097/Wicca-A-Guide-for-the-Solitary-Practitioner-by-Scott-Cunningham.pdf
    • http://loaminoo.linkpc.net/3098095094094095/Schema-Therapy-A-Practitioner-s-Guide-by-Jeffrey-E-Young.pdf
    • http://loaminoo.linkpc.net/8092094095094098/Mental-Health-Practitioner-s-Guide-to-Hiv-AIDS-by-Sana-Loue.pdf
    • http://loaminoo.linkpc.net/3098096095091092/Cognitive-Therapy-Techniques-First-Edition-A-Practitioner-s-Guide-by-Robert-L-Leahy.pdf
    • http://loaminoo.linkpc.net/1091096090094099091/Practicing-Presence-A-Guide-For-The-Spiritual-Teacher-And-Health-Practitioner-by-Eckhart-Tolle.pdf
    • http://loaminoo.linkpc.net/1090095096098093096/InterGest-Investment-Guide-The-Netherlands-by-Rumo-De-Schutter.pdf
    • http://loaminoo.linkpc.net/1091091095096095096/Child-Health-and-Behavioral-Medicine-A-Special-Issue-of-the-International-Journal-of-Behavioral-Medicine-by-Jan-Wallander.pdf
    • http://loaminoo.linkpc.net/7092090091096096/Overcoming-Paranoid-amp-Suspicious-Thoughts-A-Self-Help-Guide-Using-Cognitive-Behavioral-Techniques-by-Daniel-B-Freeman.pdf
    • http://loaminoo.linkpc.net/4092098098090/How-to-Read-a-Book-The-Classic-Guide-to-Intelligent-Reading-by-Mortimer-J-Adler.pdf
    • http://loaminoo.linkpc.net/3096095095096099/The-Politically-Incorrect-Guide-to-Darwinism-and-Intelligent-Design-by-Jonathan-Wells.pdf
    • http://loaminoo.linkpc.net/9091092099098097/What-Works-on-Wall-Street-A-Guide-to-the-Best-Performing-Investment-Strategies-of-All-Time-by-James-P-O-39-Shaughnessy.pdf
    • http://loaminoo.linkpc.net/6090099093092094/Your-Guide-to-Florida-Property-Investment-for-Global-Buyers-Owning-Investing-and-Enjoying-the-Florida-Lifestyle-by-Lee-Mirman.pdf
    • http://loaminoo.linkpc.net/5092090095090093/How-to-Import-Wine-An-Insider-s-Guide-by-Deborah-M-Gray.pdf
    • http://loaminoo.linkpc.net/4099091095095093/Men-Are-from-Mars-Women-Are-from-Venus-The-Classical-Guide-to-Understanding-the-Opposite-Sex-by-John-Gray.pdf
    • http://loaminoo.linkpc.net/7091094091099096/Mars-and-Venus-in-the-Bedroom-A-Guide-to-Lasting-Romance-and-Passion-by-John-Gray.pdf
    • http://loaminoo.linkpc.net/6094090094093098/John-Wesley-s-Sermons-An-Anthology-by-John-Wesley.pdf
    • http://loaminoo.linkpc.net/2097091098099091/How-To-Pray-The-Best-of-John-Wesley-on-Prayer-by-John-Wesley.pdf
    • http://loaminoo.linkpc.net/7098095094095097/Setting-Limits-with-Your-Strong-Willed-Child-Eliminating-Conflict-by-Establishing-Clear-Firm-and-Respectful-Boundaries-by-Robert-J-MacKenzie.pdf
    • http://loaminoo.linkpc.net/1091096090094099091/Practicing-Presence-A-Guide-For-The-Spiritual-Teacher-And-Health-Practitioner-by-E