Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4afd9f501e05317…

MALICIOUS

PDF

17.1 KB Created: 2019-05-06 19:47:42 +01:00 Authoring application: mPDF 5.7
MD5: 91ea4d37b85c43c8622cb72abc521402 SHA-1: 008fb5d1fceb47c8bf39e7ab9dc7dfd1019819d8 SHA-256: e4afd9f501e05317e8cba45fea25a0ee182b4cbdd5ece596978144461f225e3c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various external URLs, suggesting a link farm or redirection scheme. No scripts were extracted from this sample. The primary attack pattern observed is the distribution of numerous external links within the document body.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099092095090097/Funk-Justice-15-Fixes-for-Your-Ministry-Funks-by-Tami-Rowbotham.pdf
    • http://loaminoo.linkpc.net/8099092095090091/Funk-on-Parables-Collected-Essays-by-Robert-W-Funk.pdf
    • http://loaminoo.linkpc.net/7096095090093093/Jesus-Justice-and-Gender-Roles-A-Case-for-Gender-Roles-in-Ministry-by-Kathy-Keller.pdf
    • http://loaminoo.linkpc.net/3093098095094090/Tami-Hoag-CD-Collection-1-Night-Sins-and-Guilty-as-Sin-by-Tami-Hoag.pdf
    • http://loaminoo.linkpc.net/8099092093099092/Alora-Funk--The-Deliverance-Alora-Funk-1-by-Stephanie-Daich.pdf
    • http://loaminoo.linkpc.net/8099092094093093/Om-atomkrigens-betydning-for-Vilhelm-Funks-ungdom-by-Jan-Sonnergaard.pdf
    • http://loaminoo.linkpc.net/1099090096096/Edward-Carpenter-A-Life-of-Liberty-and-Love-by-Sheila-Rowbotham.pdf
    • http://loaminoo.linkpc.net/4093091097097097/Have-I-Got-a-Guy-for-You-What-Really-Happens-When-Mom-Fixes-You-Up-by-Alix-Strauss.pdf
    • http://loaminoo.linkpc.net/4094090096090096/Rebel-Crossings-New-Women-Free-Lovers-and-Radicals-in-Britain-and-the-United-States-by-Sheila-Rowbotham.pdf
    • http://loaminoo.linkpc.net/1091093095096097091/Fast-Fixes-with-Mixes-314-Delicious-No-Fuss-Recipes-by-Taste-of-Home.pdf
    • http://loaminoo.linkpc.net/3090098093093096/Fast-Fixes-with-Mixes-355-Delicious-Recipes-from-Simple-Starters-by-Taste-of-Home.pdf
    • http://loaminoo.linkpc.net/2097095095091090/Hack-Your-Writing-Seven-Search-Function-Fixes-That-Instantly-Elevate-Your-Manuscript-by-May-Dawney.pdf
    • http://loaminoo.linkpc.net/9092096091099096/The-Justice-Trilogy-Justice-and-Her-Brothers-Dustland-and-the-Gathering-by-Virginia-Hamilton.pdf
    • http://loaminoo.linkpc.net/3094098095095093/Imperfect-Justice-Cowboy-Justice-Association-6-by-Olivia-Jaymes.pdf
    • http://loaminoo.linkpc.net/4097095094093095/Redeeming-Justice-Justice-Brothers-3-by-Suzanne-Halliday.pdf
    • http://loaminoo.linkpc.net/4092090097099091/Open-Range-Justice-Mr-Justice-3-by-Chet-Cunningham.pdf
    • http://loaminoo.linkpc.net/4090093098093091/Broken-Justice-Justice-Brothers-1-by-Suzanne-Halliday.pdf
    • http://loaminoo.linkpc.net/8099092095091091/Of-Ice-and-Men-by-McKenzie-Funk.pdf
    • http://loaminoo.linkpc.net/8099092095090090/The-Funk-Wag-from-A-to-Z-by-Mel-Chin.pdf
    • http://loaminoo.linkpc.net/3091090093095093/Wasted-Justice-Justice-4-by-Diane-Capri.pdf
    • http://loaminoo.linkpc.net/1091093095096097091/Fast-Fixes-with-Mixes-314-Delicious-No-Fuss-Reci