Malicious PDF — malware analysis report

Static analysis result for SHA-256 d715620a811a0742…

MALICIOUS

PDF

18.0 KB Created: 2019-04-28 13:13:49 +01:00 Authoring application: mPDF 5.7
MD5: 415bc408f6af0dfff5fa259e4daec92c SHA-1: 1a263bc9c7bdf598a67c020f9684af6324cdfdd0 SHA-256: d715620a811a07423516cce1258d68415efd8bfa4323bde4531376cb7080a6d7
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a link farm intended for SEO manipulation or potentially to host malicious content. The SE_URGENCY_LURE heuristic indicates the document may contain deceptive text, further supporting a malicious intent. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097091096092096/Siren-Unleashed-Texas-Sirens-7-by-Sophie-Oak.pdf
    • http://loaminoo.linkpc.net/6091099093091096/The-Storm-Siren-Trilogy-Storm-Siren-Siren-s-Fury-Siren-s-Song-by-Mary-Weber.pdf
    • http://loaminoo.linkpc.net/3097094097094097/Lorelei-and-the-Sirens-The-Sirens-1-by-Aaronni-Miller.pdf
    • http://loaminoo.linkpc.net/6091099092098095/Since-the-Sirens-Sirens-of-the-Zombie-Apocalypse-1-by-E-E-Isherwood.pdf
    • http://loaminoo.linkpc.net/2095095095098091/Texas-Destiny-Texas-Glory-Texas-Splendor-Leigh-Brothers-Texas-Trilogy-1-3-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2095091095099098/Birdwoman-Memoirs-of-a-Lovesick-Siren-Diaries-of-a-Siren-Book-1-by-Anne-Carlisle.pdf
    • http://loaminoo.linkpc.net/2099093099/Siren-s-Song-Storm-Siren-3-by-Mary-Weber.pdf
    • http://loaminoo.linkpc.net/1091093098/Siren-s-Fury-Storm-Siren-2-by-Mary-Weber.pdf
    • http://loaminoo.linkpc.net/1098092091093096/The-Siren-s-Son-The-Siren-Legacy-1-by-Helen-Scott.pdf
    • http://loaminoo.linkpc.net/5098098094097091/Star-Wars-The-Force-Unleashed-II-The-Force-Unleashed-2-by-W-Haden-Blackman.pdf
    • http://loaminoo.linkpc.net/6096099092099/The-Force-Unleashed-Star-Wars-The-Force-Unleashed-1-by-Sean-Williams.pdf
    • http://loaminoo.linkpc.net/4099090095095099/Last-Chance-Reunion-Texas-Cold-Case-Texas-Lost-and-Found-Chance-Texas-4-by-Linda-Conrad.pdf
    • http://loaminoo.linkpc.net/2090090093094098/Heart-of-Texas-Vol-1-Lonesome-Cowboy-Texas-Two-Step-Heart-of-Texas-1-2-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/4093091096095093/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/5098096098093097/Nothing-Stopped-Sophie-The-Story-of-Unshakable-Mathematician-Sophie-Germain-by-Cheryl-Bardoe.pdf
    • http://loaminoo.linkpc.net/2094094094090090/Sophie-s-Snail-Sophie-1-by-Dick-King-Smith.pdf
    • http://loaminoo.linkpc.net/4093091098098093/Siren-Song-Siren-Song-Trilogy-1-by-B-A-Blackwood.pdf
    • http://loaminoo.linkpc.net/2095095093097094/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/4097096094095095/A-Match-Made-in-Texas-Deep-in-the-Heart-of-Texas-6-by-Katie-Lane.pdf
    • http://loaminoo.linkpc.net/2093090094097090/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf