Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1c959b06ca9b682…

MALICIOUS

PDF

25.4 KB Created: 2019-05-02 17:22:43 +01:00 Authoring application: mPDF 5.7
MD5: 90bc07c25cdf68d2bae881db9bd3f579 SHA-1: 78a373121d062e296febb4cf0de2f42f0c04511c SHA-256: f1c959b06ca9b68216f7f28c1da394c28b25199bd85170bb3e44e992491eac5e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented as book titles, suggesting a social engineering tactic to entice users to click. While the document body is corrupted, the presence of numerous external links points towards a link farm or redirection scheme. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094095094091098/What-Next-The-Millennial-s-Guide-to-Surviving-and-Thriving-in-the-Real-World-by-Michael-Price.pdf
    • http://loaminoo.linkpc.net/1091094092090098099/Food-Allergy-Survival-Guide-Surviving-and-Thriving-with-Food-Allergies-and-Sensitivities-by-Vesanto-Melina.pdf
    • http://loaminoo.linkpc.net/9094092094091091/Keeping-It-Real-in-an-Unreal-World-Staying-as-Real-as-Possible-in-a-World-of-Illusion-by-Michael-Jean-Nystrom-Schut.pdf
    • http://loaminoo.linkpc.net/4097092095093/Multiple-Bles8ings-Surviving-to-Thriving-with-Twins-and-Sextuplets-by-Jon-Gosselin.pdf
    • http://loaminoo.linkpc.net/5094099090095/Startup-Life-Surviving-and-Thriving-in-a-Relationship-with-an-Entrepreneur-by-Brad-Feld.pdf
    • http://loaminoo.linkpc.net/3097099096091096/Wounded-Warrior-Wounded-Wife-Not-Just-Surviving-But-Thriving-by-Barbara-McNally.pdf
    • http://loaminoo.linkpc.net/2099091098090090/Power-Surviving-and-Thriving-After-Narcissistic-Abuse-A-Collection-of-Essays-on-Malignant-Narcissism-and-Recovery-from-Emotional-Abuse-by-Shahida-Arabi.pdf
    • http://loaminoo.linkpc.net/3094094091093090/Upstairs-amp-Downstairs-The-Illustrated-Guide-to-the-Real-World-of-Downton-Abbey-by-Sarah-Warwick.pdf
    • http://loaminoo.linkpc.net/6099098097095090/Entry-Level-Life-A-Complete-Guide-to-Masquerading-as-a-Member-of-the-Real-World-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/5092098092091090/Millennial-Money-Simple-and-Easy-Personal-Finance-So-You-Can-Have-Your-Avocado-Toast-and-Eat-It-Too-by-Michael-Gombrich.pdf
    • http://loaminoo.linkpc.net/1098093092090091/Never-Too-Late-to-Go-Vegan-The-Over-50-Guide-to-Adopting-and-Thriving-on-a-Plant-Based-Diet-by-Carol-J-Adams.pdf
    • http://loaminoo.linkpc.net/7097093094094090/Whiskey-The-Definitive-World-Guide-by-Michael-James-Jackson.pdf
    • http://loaminoo.linkpc.net/3096096098093098/Body-Drama-Real-Girls-Real-Bodies-Real-Issues-Real-Answers-by-Nancy-Amanda-Redd.pdf
    • http://loaminoo.linkpc.net/6092094098096097/Real-Estate-Treasure-Map-Your-Personal-Guide-to-Real-Estate-Riches-by-Tim-Harris.pdf
    • http://loaminoo.linkpc.net/6091095099090093/SHTF-A-Guide-to-Surviving-Almost-Anything-by-Jarhead-Survivor.pdf
    • http://loaminoo.linkpc.net/3092099098091092/Beyond-the-MBA-Hype-A-Guide-to-Understanding-and-Surviving-B-Schools-by-Sameer-Kamat.pdf
    • http://loaminoo.linkpc.net/8096093097092091/The-Girlfriends-Guide-to-Surviving-the-First-Year-of-Motherhood-by-Vicki-Iovine.pdf
    • http://loaminoo.linkpc.net/1094095099093093/Surviving-Seduction-The-Shattered-World-2-by-Maia-Underwood.pdf
    • http://loaminoo.linkpc.net/6092092092099097/One-Survivor-s-Guide-for-Beating-Depression-and-Thriving-Thereafter-Simple-Practical-Step-by-Step-Remedies-for-the-Illness-of-Depression-by-Nima-Fard.pdf
    • http://loaminoo.linkpc.net/9094097091095/Prepare-For-The-Worst-And-Pray-For-The-Best-A-Layman-s-Guide-To-Surviving-A-Nation-Gone-Bad-by-Ronald-A-Martin-Jr-.pdf
    • http://loaminoo.linkpc.net/4097092095093/Mu