Malicious PDF — malware analysis report

Static analysis result for SHA-256 db1a7196e2837785…

MALICIOUS

PDF

20.9 KB Created: 2019-05-02 05:45:09 +01:00 Authoring application: mPDF 5.7
MD5: 543525a999169609f6cc110a15df8511 SHA-1: 3f244aa28bb53e02a5a8134c01ee515fe3a3100f SHA-256: db1a7196e283778557fbe842d02cdd6cec3f15b4390a09704e3f31ef7923441e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the 'linkpc.net' domain. This technique is often used for SEO poisoning or to distribute malicious content indirectly. While the document body itself is unreadable, the heuristic 'PDF_SEO_LINK_FARM' strongly indicates a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090098090094090099/Pioneers-of-photography-An-album-of-pictures-and-words-by-Aaron-Scharf.pdf
    • http://loaminoo.linkpc.net/8090094096096/Northwest-Rainforest-Pioneers-Narratives-amp-Photography-by-Claudia-Harper.pdf
    • http://loaminoo.linkpc.net/1091099092098099090/My-Family-Album-Thirty-Years-of-Primate-Photography-by-Frans-de-Waal.pdf
    • http://loaminoo.linkpc.net/7097095091090092/Digital-Photography-Masterclass-Advanced-Photographic-and-Image-Manipulation-Techniques-for-Creating-Perfect-Pictures-by-Tom-Ang.pdf
    • http://loaminoo.linkpc.net/4097098099092096/A-Life-in-Words-and-Pictures-by-Jim-Starlin.pdf
    • http://loaminoo.linkpc.net/2099097096098092/Words-Into-Pictures-E-E-Cummings-Art-Across-Borders-by-Zeno-Vernyik.pdf
    • http://loaminoo.linkpc.net/3097092098091098/Drawing-Words-and-Writing-Pictures-by-Jessica-Abel.pdf
    • http://loaminoo.linkpc.net/2099096092092093/The-Diary-of-a-Teenage-Girl-An-Account-in-Words-and-Pictures-by-Phoebe-Gloeckner.pdf
    • http://loaminoo.linkpc.net/1091090097097094094/73-Things-That-Make-Me-Say-Bad-Words-by-Aaron-Buche.pdf
    • http://loaminoo.linkpc.net/2092099090095094/Anne-Frank-Her-life-in-words-and-pictures-from-the-archives-of-The-Anne-Frank-House-by-Menno-Metselaar.pdf
    • http://loaminoo.linkpc.net/6095095090098099/Photography-Photography-Lighting-Hacks-7-Must-Know-Lighting-Tips-For-Dramatically-Stunning-Photos-Every-Time-by-Eric-Adamo.pdf
    • http://loaminoo.linkpc.net/4096098099091096/Tell-Me-Why-The-Beatles-Album-By-Album-Song-By-Song-The-Sixties-And-After-by-Tim-Riley.pdf
    • http://loaminoo.linkpc.net/3090094090096093/Home-Run-The-Picture-Life-of-Henry-Aaron-by-Hank-Aaron.pdf
    • http://loaminoo.linkpc.net/1090098090094094096/Grace-amp-the-Ice-Prince-by-J-L-Scharf.pdf
    • http://loaminoo.linkpc.net/1090098090094091091/Scharf-auf-den-Lehrer-by-Laura-Abensberg.pdf
    • http://loaminoo.linkpc.net/7091090093096094/Magic-Words-The-Science-and-Secrets-Behind-Seven-Words-That-Motivate-Engage-and-Influence-by-Tim-David.pdf
    • http://loaminoo.linkpc.net/1090098090092099090/Worldwide-Gothic-A-Chronicle-of-a-Tribe-by-Natasha-Scharf.pdf
    • http://loaminoo.linkpc.net/8094094097093099/Words-Upon-Words-The-Anagrams-Of-Ferdinand-De-Saussure-by-Jean-Starobinski.pdf
    • http://loaminoo.linkpc.net/1090098090092099097/Winning-at-Poker-Essential-Hints-amp-Tips-by-Dave-Scharf.pdf
    • http://loaminoo.linkpc.net/8095093098093090/The-Zoomable-Universe-An-Epic-Tour-Through-Cosmic-Scale-from-Almost-Everything-to-Nearly-Nothing-by-Caleb-Scharf.pdf
    • http://loaminoo.linkpc.net/2099097096098092/Words-Into-Pi