Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8b0b83c5c2ebd47…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 05:30:49 +01:00 Authoring application: mPDF 5.7
MD5: 5cd041a8093fa40e0570598a2571a5ed SHA-1: 016d7829e9ca652642dddca7dea0e8f2581671e7 SHA-256: e8b0b83c5c2ebd474b510cee20a886e7d3679ab270f3b9201e8bf649cfa4f6c6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on a dynamic DNS domain. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious content. No scripts were extracted, and the document body primarily consists of these links and metadata.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/1090095096092093098/Harriet-Beecher-Stowe---Uncle-Tom-s-Cabin-quot-We-First-Make-Our-Habits-Then-Our-Habits-Make-Us-quot-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/6091099099090096/Uncle-Tom-s-Cabin-Or-Life-Among-the-Lowly-1852-by-Harriet-Beecher-Stowe-The-REV-James-Sherman-21-February-1796---15-February-1862-Was-an-English-Congregationalist-Minister-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/3095093095098097/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091093098093099098/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/7090094098091099/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091097093091098096/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5097090093098095/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5092097099099095/Uncle-Tom-s-Cabin-or-Life-among-the-Lowly-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5098098091090093/Uncle-Tom-s-Cabin-The-Original-Classics---Illustrated-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090098092090093095/Onkel-Toms-H-tte-Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/2095091092097095/12-Years-A-Slave-True-story-of-an-African-American-who-was-kidnapped-in-New-York-and-sold-into-slavery---with-bonus-material-Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/1091092090097098096/Life-Of-Harriet-Beecher-Stowe-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5098099096090099/A-Cabana-do-Pai-Tom-s-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090093090095093096/Agnes-of-Sorrento-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/2097093097098099/Pink-and-White-Tyranny-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091091090092095095/De-hut-van-oom-Tom-Een-verhaal-uit-het-slavenleven-in-Noord-Amerika-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/8095097092098099/Pink-and-White-Tyranny-a-Society-Novel-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090098094096/A-Picture-Book-of-Harriet-Beecher-Stowe-by-David-A-Adler.pdf
    • http://loaminoo.linkpc.net/4095090094090/Harriet-Beecher-Stowe-A-Spiritual-Life-by-Nancy-Koester.pdf
    • http://loaminoo.linkpc.net/1091092090098095094/The-Pearl-of-Orr-s-Island-A-Story-of-the-Coast-of-Maine-by-Harriet-Beecher-Stowe.pdf