Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca315ac700d03472…

MALICIOUS

PDF

17.6 KB Created: 2019-05-02 18:32:44 +01:00 Authoring application: mPDF 5.7
MD5: 95f9c0ee32d285886a4639033597d99e SHA-1: 837d0d501f5e077822a4e50fc9f79e78b5484198 SHA-256: ca315ac700d03472e8dea489e609cef76af164e0954845bbe77f74ad606aae3a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, likely for SEO manipulation or to host a large number of redirectors. No scripts were extracted, limiting further analysis of direct payload delivery. The attack pattern is inferred from the link farm structure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090093097098098094/Country-Remedies-From-Pantry-Field-amp-Garden-by-Karen-Thesen.pdf
    • http://loaminoo.linkpc.net/1090096099094098095/Sarrazins-Thesen-Auf-Dem-Pr-fstand-Eine-Empirische-Widerlegung-Zentraler-Thesen-Thilo-Sarrazins-Mit-Bezug-Auf-Muslime-In-Deutschland-by-Naika-Foroutan.pdf
    • http://loaminoo.linkpc.net/1091092092090097097/The-Country-Almanac-of-Home-Remedies-Time-Tested-amp-Almost-Forgotten-Wisdom-for-Treating-Hundreds-of-Common-Ailments-Aches-amp-Pains-Quickl-by-Chrystle-Fiedler.pdf
    • http://loaminoo.linkpc.net/9099092095097099/A-Twisted-Garden-by-Simon-Quellen-Field.pdf
    • http://loaminoo.linkpc.net/2094090091094098/Cat-s-Eyes-Land-of-Miu-1-by-Karen-Lee-Field.pdf
    • http://loaminoo.linkpc.net/1090091096093099092/Trees-Shrubs-and-Vines-of-the-Texas-Hill-Country-A-Field-Guide-by-Jan-Wrede.pdf
    • http://loaminoo.linkpc.net/5093092099095094/Home-Remedies-for-Cold-Sores---Natural-Cold-Sore-Remedies-that-Work-by-Connie-Bus.pdf
    • http://loaminoo.linkpc.net/4098093096095090/Paradise-in-Plain-Sight-Lessons-from-a-Zen-Garden-by-Karen-Maezen-Miller.pdf
    • http://loaminoo.linkpc.net/1096097098093095/For-King-and-Country-The-Saga-of-Thistles-and-Roses-The-Warrior-Queen-1-by-Karen-Gray.pdf
    • http://loaminoo.linkpc.net/9095090099091097/The-Gardener-amp-the-Grill-The-Bounty-of-the-Garden-Meets-the-Sizzle-of-the-Grill-by-Karen-Adler.pdf
    • http://loaminoo.linkpc.net/3091091097096090/The-Land-of-Miu-Land-of-Miu-1-2nd-ed-by-Karen-Lee-Field.pdf
    • http://loaminoo.linkpc.net/9095090095096097/Deli-Meats-An-Italian-Pantry-by-Carla-Bardi.pdf
    • http://loaminoo.linkpc.net/8099098092098091/What-the-Fork-Are-You-Eating-An-Action-Plan-for-Your-Pantry-and-Plate-by-Stefanie-Sacks.pdf
    • http://loaminoo.linkpc.net/3091090096098091/Canning-for-a-New-Generation-Bold-Fresh-Flavors-for-the-Modern-Pantry-by-Liana-Krissoff.pdf
    • http://loaminoo.linkpc.net/1090093098090099094/The-Way-Back-by-Hjalmar-Thesen.pdf
    • http://loaminoo.linkpc.net/1090093098090099097/Bond-Of-The-Sea-A-Novel-by-Hjalmar-Thesen.pdf
    • http://loaminoo.linkpc.net/1090093098091090092/The-Receiver-by-Sharon-Thesen.pdf
    • http://loaminoo.linkpc.net/1090093097098098090/News-amp-Smoke-by-Sharon-Thesen.pdf
    • http://loaminoo.linkpc.net/1090093097098098093/The-Echoing-Cliffs-by-Hjalmar-Thesen.pdf
    • http://loaminoo.linkpc.net/1090093097098098096/Holding-The-Pose-by-Sharon-Thesen.pdf
    • http://loaminoo.linkpc.net/1090091096093099092/Trees-Shrubs-and-Vines-of-the-Texas-Hill-Country-A-Field-Guid