Malicious PDF — malware analysis report

Static analysis result for SHA-256 f057bdc8745d968a…

MALICIOUS

PDF

13.9 KB Created: 2019-05-01 17:50:04 +01:00 Authoring application: mPDF 5.7
MD5: 497bc62a2e60b73bd426b0cc5d69907e SHA-1: 71638c3a673cb790ee79c1dca786bca00979c9bf SHA-256: f057bdc8745d968a082aea351836fe843d2694e9776b8c88dbe0112dfb55aefc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to either distribute malware or engage in SEO manipulation. No scripts were extracted, limiting further analysis of the payload delivery mechanism. The attack pattern is likely a lure to entice users to click on these links, potentially leading to further compromise.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/1095090094091095/Robbie-Burns-Witch-Hunter-by-Gordon-Rennie.pdf
    • http://loaminoo.linkpc.net/9092095098091099/Starship-Troopers-by-Gordon-Rennie.pdf
    • http://loaminoo.linkpc.net/4093095093097094/Shadow-Point-The-Gothic-War-2-by-Gordon-Rennie.pdf
    • http://loaminoo.linkpc.net/8090097095099099/Execution-Hour-The-Gothic-War-1-by-Gordon-Rennie.pdf
    • http://loaminoo.linkpc.net/7096091093091096/The-Witch-Hunter-Witch-Hunter-Saga-1-by-Nicole-R-Taylor.pdf
    • http://loaminoo.linkpc.net/7093095091092/The-Witch-Hunter-The-Witch-Hunter-1-by-Virginia-Boecker.pdf
    • http://loaminoo.linkpc.net/1092090096093093/The-Witch-Hunter-The-Witch-Hunter-1-by-Virginia-Boecker.pdf
    • http://loaminoo.linkpc.net/3098098094097098/One-Night-Burns-Vampires-of-Livix-Trilogy-1-by-J-Gordon-Smith.pdf
    • http://loaminoo.linkpc.net/3098092093094094/The-Witch-s-Revenge-by-Linda-Gordon.pdf
    • http://loaminoo.linkpc.net/7090093093098098/Robbie-Shepherd-s-Doric-Columns-by-Robbie-Shepherd.pdf
    • http://loaminoo.linkpc.net/1097095096090099/Witch-Hunter-by-Virginia-Boecker.pdf
    • http://loaminoo.linkpc.net/7098094093091091/Matthias-Thulmann-Witch-Hunter-by-C-L-Werner.pdf
    • http://loaminoo.linkpc.net/6090092092090094/Vigilante-Witch-Hunter-by-Gary-Turcotte.pdf
    • http://loaminoo.linkpc.net/3098097093094/Hexed-The-Witch-Hunter-1-by-Michelle-Krys.pdf
    • http://loaminoo.linkpc.net/1099094098093091/Hollywood-Witch-Hunter-by-Valerie-Tejeda.pdf
    • http://loaminoo.linkpc.net/8096093095093092/Tales-of-a-Redheaded-Sea-Witch-Black-Depths-1-by-J-E-Hunter.pdf
    • http://loaminoo.linkpc.net/3094090091097092/The-Witch-Hunter-s-Tale-Midwife-Mysteries-3-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/1097096097097097/1602-Witch-Hunter-Angela-by-Marguerite-Bennett.pdf
    • http://loaminoo.linkpc.net/4095099095090094/The-Return-Witch-Hunter-Saga-2-by-Nicole-R-Taylor.pdf
    • http://loaminoo.linkpc.net/2090096094097095/The-Return-Witch-Hunter-Saga-2-by-Nicole-R-Taylor.pdf