Malicious PDF — malware analysis report

Static analysis result for SHA-256 e47d4055470d2ed5…

MALICIOUS

PDF

23.3 KB Created: 2019-04-30 18:00:20 +01:00 Authoring application: mPDF 5.7
MD5: 6446000b006d7616f8918fcfb1c025f5 SHA-1: 5295c42b46171a75ccc09277f76817ebe87ee426 SHA-256: e47d4055470d2ed5f24202eac1ccc90a5b614a83ae021d100b9bd93624a10d0c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on a dynamic DNS domain. This pattern is indicative of SEO poisoning or a link farm used to distribute malicious content. While no scripts were extracted, the sheer volume of links suggests a coordinated effort to direct users to potentially harmful resources. The URLs themselves are the primary IOCs in this case.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099092091096092/Demokratie-in-Europa-Und-Europaische-Demokratien-Festschrift-Fur-Heidrun-Abromeit-by-Tanja-Hitzel-Cassagnes.pdf
    • http://loaminoo.linkpc.net/1091097091096090095/Europaische-Staaten-Oder-Wo-Endet-Europa-by-Michaela-Wittinger.pdf
    • http://loaminoo.linkpc.net/1091090098099090094/Europaische-Entwicklungsroman-in-Europa-Und-Ubersee-Literarische-Lebensentwurfe-Der-Neuzeit-by-Heinz-Hillmann.pdf
    • http://loaminoo.linkpc.net/1090096090094090097/Italien-Und-Europa-Festschrift-Fuer-Hartmut-Ullrich-Zum-65-Geburtstag-by-Annette-Junemann.pdf
    • http://loaminoo.linkpc.net/1090096095099091090/Der-Grundsatz-Der-Verhaltnismassigkeit-in-Europaischen-Rechtsordnungen-Europaische-Gemeinschaft-Europaische-Menschenrechtskonvention-Bundesrepublik-by-Hans-Kutscher.pdf
    • http://loaminoo.linkpc.net/9092092091098093/Europa-Vasconica---Europa-Semitica-Trends-in-Linguistics-Studies-and-Monographs-by-Theo-Vennemann.pdf
    • http://loaminoo.linkpc.net/9099099099094099/Europa-Europa-1-3-by-Joseph-Robert-Lewis.pdf
    • http://loaminoo.linkpc.net/1091095099090097098/Warum-Sind-Demokratien-in-Zielkonflikten-Schlechte-Demokratieforderer-by-Janette-Uhlmann.pdf
    • http://loaminoo.linkpc.net/1090099090094095099/Europaische-Sozialpolitik-by-Winfried-Schm-hl.pdf
    • http://loaminoo.linkpc.net/7096093097097094/Internes-Personalmarketing-in-Kmu-by-Neumann-Tanja.pdf
    • http://loaminoo.linkpc.net/1090092095099097095/Deutschland-in-Europa---Europa-in-Deutschland-by-Helga-Seel.pdf
    • http://loaminoo.linkpc.net/1090099090095090094/Europaische-Arbeits--Und-Sozialpolitik-by-Berndt-Keller.pdf
    • http://loaminoo.linkpc.net/1090091097095091094/Turkei-Und-Europaische-Gemeinschaft-by-Zentrum-F-Ur-T-Urkeistudien.pdf
    • http://loaminoo.linkpc.net/8099094096099093/Das-Haus-der-Hebamme-Roman-by-Tanja-Wekwerth.pdf
    • http://loaminoo.linkpc.net/1090094094091096098/The-X-Zwielicht-Dark-Thriller-by-Tanja-Feiler.pdf
    • http://loaminoo.linkpc.net/9098096095098099/Ueber-Die-Anatomie-Des-Eichenholzes-Inaugural-Dissertation-Zur-Erlangung-Der-Doctorw-rde-Von-Der-Philosophischen-Facult-t-Der-Albertus-Universit-t-in-K-nigsberg-in-Pr-Genehmigt-Und-Donnerstag-Den-10-Juli-1884-Um-12-Uhr-Nebst-Den-Angef-hrten-These-by-Johannes-Abromeit.pdf
    • http://loaminoo.linkpc.net/8099094096099097/XXL-Leseprobe-Esthers-Garten-Roman-by-Tanja-Wekwerth.pdf
    • http://loaminoo.linkpc.net/9092091097090095/Weltuntergang-ALS-Erlebnis-Apokalyptische-Erzahlungen-in-Den-Massenmedien-by-Tanja-Busse.pdf
    • http://loaminoo.linkpc.net/1090093094098091098/Der-Taugenichts-by-Heidrun-B-hm.pdf
    • http://loaminoo.linkpc.net/1091090092091090094/Verfall-der-Demokratie-im-Neoliberalismus-by-Tim-Bohle.pdf
    • http://loaminoo.linkpc.net