Malicious PDF — malware analysis report

Static analysis result for SHA-256 ede68b11f4eadc83…

MALICIOUS

PDF

19.7 KB Created: 2019-05-05 08:33:51 +01:00 Authoring application: mPDF 5.7
MD5: 7cb0dd95e039435fe66c0cbe9378e03f SHA-1: c7421bd2525aabf5715fcfdd562647ae86f2ba6b SHA-256: ede68b11f4eadc833b50c979aafd8441cc016dfd8719c6a456fa8138cc4a0b4f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents, all hosted on the same domain. This suggests a link farm or a method to distribute further malicious content. The document body is heavily obfuscated, making it difficult to determine the exact user-facing lure. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/2095090099099096/The-Whole-Town-s-Talking-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/5098092092096090/The-Whole-Town-s-Talking-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/3095095099093095/I-Still-Dream-about-You-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/1094094090092093/Standing-in-the-Rainbow-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/4092091093094/Daisy-Fay-and-the-Miracle-Man-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/2095091096097094/The-All-Girl-Filling-Station-s-Last-Reunion-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/1095093097099090/The-All-Girl-Filling-Station-s-Last-Reunion-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/5097095096097/The-All-Girl-Filling-Station-s-Last-Reunion-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/3097091097092097/Fried-Green-Tomatoes-at-the-Whistle-Stop-Cafe-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/5098092095093098/Flagg-s-Small-Houses-Their-Economic-Design-and-Construction-1922-by-Ernest-Flagg.pdf
    • http://loaminoo.linkpc.net/1091093097098095093/Dead-Man-Talking-and-Talking-and-Talking-by-Philip-Sorgen.pdf
    • http://loaminoo.linkpc.net/7097092094099095/Fannie-in-the-Kitchen-The-Whole-Story-From-Soup-to-Nuts-of-How-Fannie-Farmer-Invented-Recipes-with-Precise-Measurements-by-Deborah-Hopkinson.pdf
    • http://loaminoo.linkpc.net/7097092097090098/Fannie-Poems-Inspired-by-Frances-quot-fannie-quot-Benjamin-Johnston-by-Simon-Johann-Andresen.pdf
    • http://loaminoo.linkpc.net/7097092096096092/Fannie-Farmer-s-book-of-good-dinners-by-Fannie-Merritt-Farmer.pdf
    • http://loaminoo.linkpc.net/6095096093094099/Annual-Report-of-the-Town-Officers-of-the-Town-of-Barnstead-Comprising-Those-of-the-Selectmen-Treasurer-Collector-Road-Agents-School-Board-Town-Clerk-Trustees-of-the-Public-Library-Trustees-of-Trust-Funds-and-Fire-Warden-For-the-Year-Ending-Janua-by-Barnstead-New-Hampshire.pdf
    • http://loaminoo.linkpc.net/7097092095094099/The-Stories-of-Fannie-Hurst-by-Fannie-Hurst.pdf
    • http://loaminoo.linkpc.net/1099098092091092/Talking-Dirty-with-the-CEO-Talking-Dirty-1-by-Jackie-Ashenden.pdf
    • http://loaminoo.linkpc.net/1091096095092094094/Small-Town-Vbs-Three-Vbs-Programs-with-Small-Town-Heart-and-Big-Time-Ideas-by-Gennifer-Anderson.pdf
    • http://loaminoo.linkpc.net/5098092095094090/Send-for-the-Bad-Guy-by-Ethan-Flagg.pdf
    • http://loaminoo.linkpc.net/5098092094094090/FantasyCraft-by-Alex-Flagg.pdf