Malicious PDF — malware analysis report

Static analysis result for SHA-256 dbeb1ac740e88f64…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 02:46:46 +01:00 Authoring application: mPDF 5.7
MD5: 7ea2a2ea763e63a0ecf98a1278962d5c SHA-1: d2d8ee94e92833f9f8811fdb5d5c0f4cbd78f233 SHA-256: dbeb1ac740e88f649aa7a66903d90b95c37d89282d3983fcfede61d4f20019f9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates a critical finding related to this link farm, suggesting a malicious intent to direct users to external sites. While the extracted URLs are labeled as benign, the sheer volume and the heuristic firing suggest a potential for SEO manipulation or a distribution vector for other malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091099098093097/A-Dead-Man-s-Blood-A-Dark-Urban-Fantasy-Thriller-by-John-Wayne-Hawkes.pdf
    • http://loaminoo.linkpc.net/8099096095096095/Blood-Stones-An-Uncanny-Kingdom-Urban-Fantasy-The-Dark-Lakes-2-by-M-V-Stott.pdf
    • http://loaminoo.linkpc.net/1092098099096098/Mortality-Bites-An-Urban-Fantasy-Thriller-by-Ramy-Vance.pdf
    • http://loaminoo.linkpc.net/1091095093093097095/So-ruhe-in-Morpheus-Armen-mein-Kind-Thriller-mit-Urban-Fantasy-Elementen-by-Andrea-Schorn.pdf
    • http://loaminoo.linkpc.net/2099094097090096/Heroines-amp-Hellions-An-Urban-Fantasy-and-Fantasy-Collection-by-Margo-Bond-Collins.pdf
    • http://loaminoo.linkpc.net/1095099098093/Second-Skin-by-John-Hawkes.pdf
    • http://loaminoo.linkpc.net/6090092098097091/At-Last-Redemption-Thriller-6-Alex-Troutt-Thriller-6-by-John-W-Mefford.pdf
    • http://loaminoo.linkpc.net/3092093093095093/At-Bay-Redemption-Thriller-1-Alex-Troutt-Thriller-1-by-John-W-Mefford.pdf
    • http://loaminoo.linkpc.net/2099096099098095/John-Wayne-My-Father-by-Aissa-Wayne.pdf
    • http://loaminoo.linkpc.net/1092092092092097/Kiss-of-the-Fallen-A-Sensual-Urban-Fantasy-by-Kharma-Kelley.pdf
    • http://loaminoo.linkpc.net/2092091096098091/Naked-City-Tales-of-Urban-Fantasy-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/6091097090099093/Twisted-Boulevard-Tales-of-Urban-Fantasy-by-Angela-Charmaine-Craig.pdf
    • http://loaminoo.linkpc.net/3095096099093093/Elementals-A-Paranormal-Urban-Fantasy-Romance-Anthology-by-Anne-L-Parks.pdf
    • http://loaminoo.linkpc.net/5097094097097092/Transcend-An-Urban-Fantasy-Whispered-Echoes-Book-2-by-Anne-Michaud.pdf
    • http://loaminoo.linkpc.net/1098091097090098/21-Shades-of-Night-A-Collection-of-Best-Selling-Paranormal-Romance-and-Urban-Fantasy-by-Katie-de-Long.pdf
    • http://loaminoo.linkpc.net/2099090090094091/Dead-of-Night-Doc-Ford-Mystery-12-by-Randy-Wayne-White.pdf
    • http://loaminoo.linkpc.net/1090098099093094098/Searching-Dragon-Dragon-Rising-Urban-Fantasy-Series-2-by-Trudi-Jaye.pdf
    • http://loaminoo.linkpc.net/1091099091093098/Yucatan-Dead-Kate-Jones-Thriller-6-by-D-V-Berkom.pdf
    • http://loaminoo.linkpc.net/4091096093094091/Legends-of-Blood-The-Vampire-in-History-and-Myth-by-Wayne-Bartlett.pdf
    • http://loaminoo.linkpc.net/2091098099095092/Dark-Banquet-Blood-and-the-Curious-Lives-of-Blood-Feeding-Creatures-by-Bill-Schutt.pdf
    • http://loaminoo.linkpc.net/10920920920