Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcab891a253301c7…

MALICIOUS

PDF

21.8 KB Created: 2019-04-30 17:52:09 +01:00 Authoring application: mPDF 5.7
MD5: 681880812cb4e6e8aff6e48da7dd3992 SHA-1: 0e1e2ab61ede49360a6091ab7ae03516119631a4 SHA-256: dcab891a253301c7c87d4cce8fc80d60323d4bd8aa926582efc21821b3bf27af
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file exhibits a critical heuristic firing for a link farm, containing numerous embedded URLs. The document body, though heavily obfuscated, also contains these URLs, suggesting a potential attempt to distribute malicious content or manipulate search engine results. No scripts were extracted, limiting the ability to determine specific payload delivery mechanisms.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8090097099092091/In-Tune-with-the-Moon-2012-The-Complete-Day-by-Day-Moon-Planner-for-Growing-and-Living-in-2012-by-Michel-Gros.pdf
    • http://loaminoo.linkpc.net/8090097099093091/In-Tune-with-the-Moon-2013-The-Complete-Day-by-Day-Moon-Planner-for-Growing-and-Living-in-2013-by-Michel-Gros.pdf
    • http://loaminoo.linkpc.net/5096098096093091/Autonomous-and-Intelligent-Systems-Third-International-Conference-AIS-2012-Aviero-Portugal-June-25-27-2012-Proceedings-by-Mohamed-Kamel.pdf
    • http://loaminoo.linkpc.net/5098093095093097/Model-and-Data-Engineering-2nd-International-Conference-Medi-2012-Poitiers-France-October-3-5-2012-Proceedings-by-Alberto-Abell.pdf
    • http://loaminoo.linkpc.net/1090097096099091097/Computer-Algebra-in-Scientific-Computing-14th-International-Workshop-CASC-2012-Maribor-Slovenia-September-3-6-2012-Proceedings-by-Vladimir-P-Gerdt.pdf
    • http://loaminoo.linkpc.net/7091096095096098/Artificial-Intelligence-and-Soft-Computing-11th-International-Conference-Icaisa-2012-Zakopane-Poland-April-29---3-May-2012-Proceedings-Part-I-by-Leszek-Rutkowski.pdf
    • http://loaminoo.linkpc.net/8094093099090093/Cooking-for-Christmas-Special-Edition-2012-For-Dillard-s-by-Southern-Living-Inc-.pdf
    • http://loaminoo.linkpc.net/1096091095091096/Growing-Up-Untouchable-in-India-A-Dalit-Autobiography-by-Vasant-Moon.pdf
    • http://loaminoo.linkpc.net/9096092091092099/Moon-O-Theism-Religion-of-a-War-and-Moon-God-Prophet-Volume-I-of-II-by-Yoel-Natan.pdf
    • http://loaminoo.linkpc.net/1093095093098095/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/3098097096092096/In-the-Light-of-the-Full-Cold-Moon-Moon-Sage-Theosophies-1-by-Susan-Elizabeth-Girard.pdf
    • http://loaminoo.linkpc.net/7099094090092/New-Moon-Summer-Seasons-of-the-Moon-Cain-Chronicles-1-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/1090094094093098096/Hades-Moon-Pluto-in-Aspect-to-the-Moon-by-Judy-Hall.pdf
    • http://loaminoo.linkpc.net/2098093096090099/Moon-Shimmers-Otherworld-Sisters-of-the-Moon-19-by-Yasmine-Galenorn.pdf
    • http://loaminoo.linkpc.net/1091096097093090/Long-Night-Moon-Seasons-of-the-Moon-3-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/1091097093095090097/Moon-Panama-Moon-Handbooks-by-William-Friar.pdf
    • http://loaminoo.linkpc.net/9091092092093/Moon-Burning-Children-of-the-Moon-3-by-Lucy-Monroe.pdf
    • http://loaminoo.linkpc.net/2098090096099097/Black-Moon-Silver-Moon-2-by-Rebecca-A-Rogers.pdf
    • http://loaminoo.linkpc.net/9091090090099/Moon-Craving-Children-of-the-Moon-2-by-Lucy-Monroe.pdf
    • http://loaminoo.linkpc.net/1097093098092094/Blood-Moon-Silver-Moon-3-by-Rebecca-A-Rogers.pdf