Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb99bbefe1aae57a…

MALICIOUS

PDF

15.4 KB Created: 2019-05-02 18:11:58 +01:00 Authoring application: mPDF 5.7
MD5: 8fde9385b53a162c818b6dd037419af4 SHA-1: a26cadd5cf10cfd257a0f1f2d5f5e5ee6c81cc91 SHA-256: cb99bbefe1aae57a8dc4e707d7da5dd63be2d8233b983b6068270017afb1f466
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, limiting the ability to determine specific execution behaviors.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094093094095090/Wicked-Lovely-by-Jess-C-Scott.pdf
    • http://loaminoo.linkpc.net/3092099092092/Ink-Exchange-Wicked-Lovely-2-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/1091090095094091099/Wicked-Lovely-with-Bonus-Material-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/8098097098090/Stopping-Time-Wicked-Lovely-2-5-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/3096090097096096/Darkest-Mercy-Wicked-Lovely-5-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/3098095092097095/The-Wicked-Woodleys-Bundle-The-Wicked-Woodleys-1-6-by-Jess-Michaels.pdf
    • http://loaminoo.linkpc.net/1093095098096091/Stopping-Time-and-Old-Habits-Wicked-Lovely-2-5-2-6-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/1093093097092093/Sanctuary-Wicked-Lovely-Desert-Tales-1-by-Melissa-Marr.pdf
    • http://loaminoo.linkpc.net/2090094096092099/Fascinated-The-Wicked-Woodleys-6-by-Jess-Michaels.pdf
    • http://loaminoo.linkpc.net/2091093097092092/Skins-Animal-Stories-by-Jess-C-Scott.pdf
    • http://loaminoo.linkpc.net/2096090097093096/Wicked-Romance-of-a-Vampire-The-Pleasure-Of-His-Punishment-10-by-J-S-Scott.pdf
    • http://loaminoo.linkpc.net/1099096092098098/Jess-and-the-Ghost-of-Black-Rock-Castle-The-Jess-Mystery-Series-Book-1-by-Nina-Levison.pdf
    • http://loaminoo.linkpc.net/3093094090096094/The-Children-Of-Lovely-Lane-Lovely-Lane-2-by-Nadine-Dorries.pdf
    • http://loaminoo.linkpc.net/3095096097096098/Pure-Wicked-Wicked-Lovers-9-5-1001-Dark-Nights-25-by-Shayla-Black.pdf
    • http://loaminoo.linkpc.net/3090099099090090/The-Wicked-Years-Complete-Collection-Wicked-Son-of-a-Witch-A-Lion-Among-Men-and-Out-of-Oz-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/3095097097090093/Wicked-The-Life-and-Times-of-the-Wicked-Witch-of-the-West-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/1094094095094/The-Wicked-Wicked-Ladies-in-the-Haunted-House-by-Mary-Chase.pdf
    • http://loaminoo.linkpc.net/1094096097094091/Wicked-Favor-The-Wicked-Horse-Vegas-1-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/3098093097090093/Wicked-Bond-The-Wicked-Horse-5-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/2090091093093092/Wicked-My-Love-Wicked-Little-Secrets-2-by-Susanna-Ives.pdf
    • http://loaminoo.linkpc.net/2096090097093096/Wicked-Romance-of-a-Vampire-The-Pleasure-Of-His-Punishment-10-by-J-S-Scot