Malicious PDF — malware analysis report

Static analysis result for SHA-256 e89441e40b6bc3c0…

MALICIOUS

PDF

21.8 KB Created: 2019-05-04 13:58:09 +01:00 Authoring application: mPDF 5.7
MD5: 8da6f81c92a3585d3e814a545933360a SHA-1: ebaf53a4620eae699e3a9d828752bbe1f4e3eb5f SHA-256: e89441e40b6bc3c06eaf8f992634a7681d6ec58629b0190d92f529cf1d4c8fd7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. While the extracted URLs themselves are marked as benign, the sheer volume and the heuristic firing indicate a suspicious pattern. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate intent beyond linking to external resources.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090097092099096093/Schwarz-ist-die-Nacht-Die-M-rder-die-ich-Rief-Zwei-Krimis-In-Einem-Band-by-Susanne-Mischke.pdf
    • http://loaminoo.linkpc.net/1090095097096099093/Privatdetektiv-Tony-Cantrell-Sammelband-6---F-nf-Krimis-in-einem-Band-by-A-F-Morland.pdf
    • http://loaminoo.linkpc.net/1090095097096098097/Privatdetektiv-Tony-Cantrell-Sammelband-7---F-nf-Krimis-in-einem-Band-by-A-F-Morland.pdf
    • http://loaminoo.linkpc.net/1091095098092095096/Die-Frau-Im-Rollstuhl-Shooting-Stars-2-Nick-Sharman-Krimis-In-Einem-Band-by-Mark-Timlin.pdf
    • http://loaminoo.linkpc.net/9094099090099091/Wie-du-mir-so-ich-dir-and-Jacke-wie-Hose-Zwei-Romane-in-einem-Band-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/6095098095091099/Mein-Kampf-zwei-B-nde-in-einem-Band-by-Adolf-Hitler.pdf
    • http://loaminoo.linkpc.net/1090091099097092097/Tuareg-Bocanegra-Zwei-Romane-In-Einem-Band-by-Alberto-V-zquez-Figueroa.pdf
    • http://loaminoo.linkpc.net/9090092096092094/Schweinsgalopp-Fliegende-Fetzen-Zwei-Scheibenwelt-Romane-in-einem-Band-by-Terry-Pratchett.pdf
    • http://loaminoo.linkpc.net/1091091098090094098/Schuld-Verj-hrt-Nicht-Phantom-In-Rot-Zwei-Romane-In-Einem-Band-by-Ruth-Rendell.pdf
    • http://loaminoo.linkpc.net/1091096096090090099/Park-Avenue-Prinzessinnen-Society-Girls-Zwei-Romane-in-einem-Band-by-Plum-Sykes.pdf
    • http://loaminoo.linkpc.net/8099094094093099/Der-Hypnotiseur-Paganinis-Fluch-Zwei-Joona-Linna-Romane-in-einem-Band-by-Lars-Kepler.pdf
    • http://loaminoo.linkpc.net/9090092092096098/Die-Stunde-der-Schwestern-amp-Das-Haus-unter-den-Zypressen-Zwei-Romane-in-einem-Band-by-Katja-Maybach.pdf
    • http://loaminoo.linkpc.net/9094099095097094/Das-tote-Land-Der-steinerne-Wolf-Zwei-Romane-in-einem-Band-Enwor-3-4-by-Wolfgang-Hohlbein.pdf
    • http://loaminoo.linkpc.net/8098096094096090/Fear-Street-Geisterstunde-Die-Nacht-des-B-sen-Drei-Schattenwelt-Romane-in-einem-Band-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1091096095099099099/Bridget-Jones-Schokolade-zum-Fr-hst-ck-Am-Rande-des-Wahnsinns-Zwei-Romane-in-einem-Band-by-Helen-Fielding.pdf
    • http://loaminoo.linkpc.net/9097096094095092/M-nner-sind-wie-Schokolade-amp-Ich-pfeif-auf-sch-ne-M-nner-Zwei-Romane-in-einem-Band-by-Tina-Grube.pdf
    • http://loaminoo.linkpc.net/1090090090096098099/Abenteuer-am-Blauen-Nil-Drei-Mann-ein-Boot-zum-Rudolfsee-Zwei-Abenteuer-in-einem-Band-by-R-diger-Nehberg.pdf
    • http://loaminoo.linkpc.net/1090097093090095097/Mordsweiber-2-by-Susanne-Mischke.pdf
    • http://loaminoo.linkpc.net/1090097092099097094/MORDSKERLE-EPISODE-1-by-Susanne-Mischke.pdf
    • http://loaminoo.linkpc.net/1090097092098094098/Winterk-sse-in-New-York-by-Susanne-Mischke.pdf
    • http://loaminoo.linkpc.net/9090092096092094/Schweinsgalopp-Fliegende-Fetzen-Zwei-Scheibenwe