Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed8769297f808742…

MALICIOUS

PDF

14.0 KB Created: 2019-04-30 02:37:30 +01:00 Authoring application: mPDF 5.7
MD5: fec1b45a897874bbbb71ea0f1f532d5a SHA-1: 85390edba08acb86836acf30a8ae8ca09ed45afe SHA-256: ed8769297f80874271981367e9999d24827f0cd35125d0daa8a63bfa59186a3d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to external content. While no scripts were extracted, the sheer volume of links points towards a malicious intent, possibly for SEO spam or to distribute further malicious payloads. The URLs themselves appear to be benign, but the pattern of distribution is suspicious.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092095093097094/Screenplays-by-Stephen-King-Rose-Red-Kingdom-Hospital-Creepshow-the-Stand-Children-of-the-Corn-Cat-s-Eye-Pet-Sematary-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/1091095098098095090/STEPHEN-KING-NEW-COVER-SERIES-No-10-JOYLAND-ILLUSTRATED---1-500-by-Stephen-King-based-on-a-book-by-.pdf
    • http://loaminoo.linkpc.net/6092092091092099/Dolores-Claiborne-Nightmares-and-Dreamscapes-Stephen-King-11-2-boxed-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4092091090094099/Stephen-King-Goes-to-the-Movies-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/6097094094093091/King-Goes-to-the-Movies-Vijf-verfilmde-verhalen-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/8094097099091/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2096093098093/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4094091099094/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/7091091095098097/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4095094097098096/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096094093095099/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/9096092096/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2093090091097091/Pet-Sematary-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2091092093092093/-Salem-s-Lot-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3094096099091094/Insomnia-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/8093097092096/Joyland-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096097098097097/Under-the-Dome-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/5092096099092097/Mobiel-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3095091091095098/Misery-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3092096095093097/Beachworld-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4095094