Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8379a0b8ae01a8c…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 05:36:25 +01:00 Authoring application: mPDF 5.7
MD5: 55a49b6e7864ed30465d68d5aad519c5 SHA-1: 3f26620882fa9f44f96625bff572936675d6c5c7 SHA-256: e8379a0b8ae01a8c724e4b61e469da4acc9ea013dca626ba3e25bf9447ff8d3e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to a domain that hosts numerous PDF files, suggesting a link farm or traffic generation scheme. While the URLs themselves are currently marked as benign, the sheer volume and structure indicate a malicious intent to redirect users. No scripts were extracted, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6093091096099097/Rowan-and-Dominic-Changing-The-Game-For-You-1-by-M-L-Bash.pdf
    • http://loaminoo.linkpc.net/6093091095094090/You-Can-Have-an-Amazing-Memory-Learn-Life-Changing-Techniques-and-Tips-from-the-Memory-Maestro-by-Dominic-O-39-Brien.pdf
    • http://loaminoo.linkpc.net/6093091094097096/Dominic-s-Quest-The-Dominic-Chronicles-2-by-F-J-Atkinson.pdf
    • http://loaminoo.linkpc.net/7099097094092/Rowan-and-the-Keeper-of-the-Crystal-Rowan-of-Rin-3-by-Emily-Rodda.pdf
    • http://loaminoo.linkpc.net/4090090092092096/Changing-the-Game-The-Parent-s-Guide-to-Raising-Happy-High-Performing-Athletes-and-Giving-Youth-Sports-Back-to-Our-Kids-by-John--O-39-Sullivan.pdf
    • http://loaminoo.linkpc.net/8091099090094/Rowan-and-the-Zebak-Rowan-of-Rin-4-by-Emily-Rodda.pdf
    • http://loaminoo.linkpc.net/4090098096092099/Changing-the-Game-Play-by-Play-2-by-Jaci-Burton.pdf
    • http://loaminoo.linkpc.net/8095093091092/Rowan-Hood-Outlaw-Girl-of-Sherwood-Forest-Rowan-Hood-1-by-Nancy-Springer.pdf
    • http://loaminoo.linkpc.net/3096096093094098/Changing-Bodies-Changing-Lives-by-Ruth-Bell.pdf
    • http://loaminoo.linkpc.net/1099091098096098/Bash-The-Rich-by-Ian-Bone.pdf
    • http://loaminoo.linkpc.net/1096090097091097/Rainbow-Bash-d-XXX-d-2-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/4096095097092096/Changing-Planet-Changing-Health-How-the-Climate-Crisis-Threatens-Our-Health-and-What-We-Can-Do-about-It-by-Paul-R-Epstein.pdf
    • http://loaminoo.linkpc.net/1090096092099091/Rowan-of-the-Wood-Rowan-of-the-Wood-1-by-Christine-Rose.pdf
    • http://loaminoo.linkpc.net/6095094098090/Rowan-of-the-Wood-Rowan-of-the-Wood-1-by-Christine-Rose.pdf
    • http://loaminoo.linkpc.net/2091099092091096/The-Inevitable-Collision-of-Birdie-amp-Bash-by-Candace-Ganger.pdf
    • http://loaminoo.linkpc.net/4099091093094094/Town-in-a-Pumpkin-Bash-A-Candy-Holliday-Mystery-4-by-B-B-Haywood.pdf
    • http://loaminoo.linkpc.net/1090093098094096091/AI-Game-Engine-Programming-Game-Development-Series-Charles-River-Media-Game-Development-by-Brian-Schwab.pdf
    • http://loaminoo.linkpc.net/3095098093090091/Bash-Volume-I-Rolling-Thunder-Motorcycle-Club-3-by-Candace-Blevins.pdf
    • http://loaminoo.linkpc.net/2099098099094091/Bash-Volume-III-Rolling-Thunder-Motorcycle-Club-5-by-Candace-Blevins.pdf
    • http://loaminoo.linkpc.net/7091091096094098/A-B-C-for-Alex-Bash-and-Company-A-to-Z-Animal-Tales-from-Around-the-World-by-Pascal-K-Soman-and-Vickie-A-Soman.pdf
    • http://loaminoo.linkpc.net/8091099090094/Rowan-and-the-Zeb