Malicious PDF — malware analysis report

Static analysis result for SHA-256 deab47e7004f81fb…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 03:57:31 +01:00 Authoring application: mPDF 5.7
MD5: 87444e98cc6e91cbc7317bd04498d64e SHA-1: 74d8f1adc224ed6d5d4fc0120ee5c32fbf8502ed SHA-256: deab47e7004f81fbbe37e967fe6c79d34d74d9d90acab8f2416057290adc48d9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The links themselves point to book titles, but the sheer volume and the heuristic firing indicate a non-standard use. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093095096/String-Theory-David-Foster-Wallace-on-Tennis-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1090092092092095092/Consider-David-Foster-Wallace-by-David-Hering.pdf
    • http://loaminoo.linkpc.net/2097091098091095/Oblivion-Stories-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/5096090090093095/L-Infinie-com-die-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/3098095094091/Consider-the-Lobster-and-Other-Essays-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1093097093098098/Infinite-Jest-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/2099092098096091/Both-Flesh-and-Not-Essays-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/4090090090090090/The-Pale-King-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/2098095093093098/Infinite-Jest-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1097090091092095/The-Broom-of-the-System-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1097099093094097/Both-Flesh-and-Not-Essays-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/3093096098092094/A-Supposedly-Fun-Thing-I-ll-Never-Do-Again-An-Essay-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/4092092094095096/Understanding-David-Foster-Wallace-by-Marshall-Boswell.pdf
    • http://loaminoo.linkpc.net/1097099092090095/The-Legacy-of-David-Foster-Wallace-by-Samuel-Cohen.pdf
    • http://loaminoo.linkpc.net/3095091098093/A-Supposedly-Fun-Thing-I-ll-Never-Do-Again-Essays-and-Arguments-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/6092090091096091/Freedom-and-the-Self-Essays-on-the-Philosophy-of-David-Foster-Wallace-by-Steven-M-Cahn.pdf
    • http://loaminoo.linkpc.net/9097096097091090/Signifying-Rappers-Rap-and-Race-in-the-Urban-Present-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/6092090091099094/Fate-Time-and-Language-An-Essay-on-Free-Will-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/8097096091099098/Schrecklich-am-sant---aber-in-Zukunft-ohne-mich-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1091092094091092099/Schrecklich-am-sant---aber-in-Zukunft-ohne-mich-by-David-Foster-Wallace.pdf
    • http://loaminoo.linkpc.net/1097099093094097/Both-Flesh-and-Not-Essays-by-Da