Malicious PDF — malware analysis report

Static analysis result for SHA-256 dbe40950703ab12b…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 02:06:12 +01:00 Authoring application: mPDF 5.7
MD5: 3dabd5dba8dde32f9560692b3b09f4d2 SHA-1: 959bc78d48d0d307d47d694698035f714c2f14d8 SHA-256: dbe40950703ab12b691b02b550ac352f0663f0fe7cabd50d3dce018cd80e4b9d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files, hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing suggests a link farm or a method to distribute malicious content indirectly. No scripts were extracted from this sample. The primary attack pattern involves redirecting users to a large collection of documents on a suspicious domain.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093098091092093/The-Life-and-Adventures-of-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/2099098099098097/The-Life-and-Adventures-of-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/1091099090090099092/A-Kidnapped-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/6093091090090/A-Kidnapped-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/1091099090091095093/Santa-Claus-Doesn-t-Mop-Floors-The-Adventures-of-the-Bailey-School-Kids-3-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/7091093092093092/The-Wonderful-Wizard-of-Oz-By-L-Frank-Baum---Illustrated-Free-Audiobook-Unabridged-Original-E-Reader-Friendly-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/8097099093092/The-Adventures-of-Trot-amp-Cap-n-Bill-Before-They-Went-to-Oz---The-Sea-Fairies-Sky-Island-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/3098093091094092/Adventures-in-Oz-Vol-II-Dorothy-and-the-Wizard-in-Oz-the-Road-to-Oz-the-Emerald-City-of-Oz-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/5098098090096092/The-Wonderful-Wizard-of-Oz-By-L-Frank-Baum---Illustrated-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/1091099090091099098/Here-Comes-Santa-Claus-by-Gene-Autry.pdf
    • http://loaminoo.linkpc.net/9091098099092091/Carving-Santa-and-Mrs-Claus-by-Ken-Blomquist.pdf
    • http://loaminoo.linkpc.net/1096099093098095/Is-there-a-Santa-Claus-by-Jacob-A-Riis.pdf
    • http://loaminoo.linkpc.net/5090092092095091/I-Believe-in-Santa-Claus-by-Diane-Adamson.pdf
    • http://loaminoo.linkpc.net/8091092097099093/Santa-Claus-Exposed-by-Guy-Incognito.pdf
    • http://loaminoo.linkpc.net/1097094094094/The-Santa-Claus-Bank-Robbery-by-A-C-Greene.pdf
    • http://loaminoo.linkpc.net/1090094091095096096/Strapse-f-r-Santa-Claus-by-Alex-Horn.pdf
    • http://loaminoo.linkpc.net/1091099090091095090/The-Year-Without-a-Santa-Claus-by-Phyllis-McGinley.pdf
    • http://loaminoo.linkpc.net/5090092093099093/Yes-Virginia-There-Is-a-Santa-Claus-by-Chris-Plehal.pdf
    • http://loaminoo.linkpc.net/1091099090090094098/Santa-Claus-The-King-of-the-Elves-by-B-C-Chase.pdf
    • http://loaminoo.linkpc.net/1091095096090091/Santa-Claus-and-Little-Sister-by-Brian-G-Snow.pdf
    • http://loaminoo.linkpc.net/7091093092093092/The-Wonderful-Wizard-of-Oz-By-L-Frank-Baum---Illustrated-Free-Audiobook-Unabridged-Original-E-Reader-Friend