Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4e6ca63e68d97d3…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 04:13:19 +01:00 Authoring application: mPDF 5.7
MD5: 87f11cf1653eab7e45816d7f76968deb SHA-1: 5e5341d8356f7430ca23d36f436c58c70f0793e7 SHA-256: d4e6ca63e68d97d32abff8cd525185bff02abf39f61be6622ff1d70d57bfd551
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. No scripts were extracted from this sample, limiting further analysis of its behavior.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3095090093098094/The-Highlander-s-Touch-Highlander-3-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/3095092092090093/The-Dark-Highlander-Highlander-5-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/4090092092097095/Kiss-of-the-Highlander-Highlander-4-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/3095094095093095/Into-the-Dreaming-Highlander-8-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/3098093096093098/Beyond-the-Highland-Mist-To-Tame-a-Highland-Warrior-Highlander-1-2-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/5090093096099096/The-Highlander-s-Desire-Highlander-Brothers-2-by-Margo-Maguire.pdf
    • http://loaminoo.linkpc.net/2090093093093/Possession-of-a-Highlander-Highlander-2-by-Madeline-Martin.pdf
    • http://loaminoo.linkpc.net/8094090099095/Secrets-of-the-Highlander-Highlander-6-by-Janet-Chapman.pdf
    • http://loaminoo.linkpc.net/4099096098093095/Highlander-In-Her-Dreams-Highlander-2-by-Allie-Mackay.pdf
    • http://loaminoo.linkpc.net/2099099093091094/The-Highlander-s-Bride-Highlander-Duo-2-by-Donna-Fletcher.pdf
    • http://loaminoo.linkpc.net/3092095094099099/Loving-the-Highlander-Highlander-2-by-Janet-Chapman.pdf
    • http://loaminoo.linkpc.net/1092092097099/Charming-the-Highlander-Highlander-1-by-Janet-Chapman.pdf
    • http://loaminoo.linkpc.net/2092097093092096/Highlander-in-Her-Dreams-Highlander-2-by-Allie-Mackay.pdf
    • http://loaminoo.linkpc.net/2093096094/Taken-by-the-Highlander-Highlander-5-by-Julianne-MacLean.pdf
    • http://loaminoo.linkpc.net/7098094099093099/Serie-Televisive-Francesi-Galactik-Football-Summer-Crush-Kung-Foot-Summer-Dreams-Highlander-Julie-Lescaut-Highlander-The-Raven-15love-by-Fonte-Wikipedia.pdf
    • http://loaminoo.linkpc.net/4091090094098094/Bloodfever-Fever-2-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/4097099094/Feversong-Fever-9-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/3092096097094/Dreamfever-Fever-4-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/2096092092090097/Faefever-Fever-3-by-Karen-Marie-Moning.pdf
    • http://loaminoo.linkpc.net/2095094094092/Bloodfever-Fever-2-by-Karen-Marie-Moning.pdf