Malicious PDF — malware analysis report

Static analysis result for SHA-256 f29f548a6561c826…

MALICIOUS

PDF

14.3 KB Created: 2019-04-30 18:56:39 +01:00 Authoring application: mPDF 5.7
MD5: 8ee0476988f9eb46e8a37aa57e38de7c SHA-1: a1df049134db2e1cf9876cc41e0eac4a811ecc99 SHA-256: f29f548a6561c82615ae640b4abf2c9fed1238b20362da091d7140d38df41324
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links are marked as benign, the sheer volume and the presence of the SE_URGENCY_LURE heuristic suggest a potential attempt to manipulate search engine results or to distribute malicious content through a link farm. No scripts were extracted, and the document body primarily consists of these links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095096093095090/Heart-of-the-Hunter-Naughty-Boy-4-by-Chance-Carter.pdf
    • http://loaminoo.linkpc.net/2094098092093091/The-Hunter-Robert-Hunter-Series-0-5-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/1092098090091095/Bad-Boy-Daddy-by-Chance-Carter.pdf
    • http://loaminoo.linkpc.net/2094098096093092/I-Am-Death-Robert-Hunter-7-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/1092098097093098/The-Executioner-Robert-Hunter-2-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/5091096093/The-Caller-Robert-Hunter-8-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/4091091099099095/Last-Chance-Robyn-Hunter-1-by-Norah-McClintock.pdf
    • http://loaminoo.linkpc.net/1092099094096096/The-Crucifix-Killer-Robert-Hunter-1-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/9093091090093096/Chance-and-Heart-by-Kade-Boehme.pdf
    • http://loaminoo.linkpc.net/2090096096090093/Enforcer-s-Heart-Stratton-Wolves-3-by-Mina-Carter.pdf
    • http://loaminoo.linkpc.net/1097094092090094/Fifty-Shades-of-Naughty-1-of-the-Fifty-Shades-of-Naughty-Trilogy-by-Edward-Naughty.pdf
    • http://loaminoo.linkpc.net/3094094096099090/Hidden-Under-Her-Heart-Chance-for-Love-2-by-Rachelle-Ayala.pdf
    • http://loaminoo.linkpc.net/2095099099094093/Cross-My-Heart-and-Hope-to-Spy-Gallagher-Girls-2-by-Ally-Carter.pdf
    • http://loaminoo.linkpc.net/3092098099097/Cross-My-Heart-and-Hope-to-Spy-Gallagher-Girls-2-by-Ally-Carter.pdf
    • http://loaminoo.linkpc.net/4094091095096090/Cross-My-Heart-and-Hope-to-Spy-Gallagher-Girls-2-by-Ally-Carter.pdf
    • http://loaminoo.linkpc.net/1090091093096097095/A-Heart-s-Forgiveness-A-Chance-Novel---Brett-amp-Julie-by-Joanne-Schwehm.pdf
    • http://loaminoo.linkpc.net/4098095091093093/Naughty-Wishes-Part-IV-Soul-Naughty-Wishes-4-by-Joey-W-Hill.pdf
    • http://loaminoo.linkpc.net/9097094092091/Heart-of-the-Hunter-by-Deon-Meyer.pdf
    • http://loaminoo.linkpc.net/6096092091095/Hunter-s-Heart-Alpha-Pack-4-by-J-D-Tyler.pdf
    • http://loaminoo.linkpc.net/6097090098093/The-Heart-Is-a-Lonely-Hunter-by-Carson-McCullers.pdf
    • http://loaminoo.linkpc.net/3092098099097/Cross-My-Heart-and-Hope-to-Spy-Gal