Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4b2245b13f3d0eb…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 18:22:31 +01:00 Authoring application: mPDF 5.7
MD5: 64d0d836c43cc2f69827dc1801805fb5 SHA-1: d592151fc2d1fb2fa93d24a9dc5d4b81a8e8b9ab SHA-256: f4b2245b13f3d0eb277bb7506aaebcad02ca927c4410ece4b9b469456560b4af
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external websites, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, also contains these URLs. This suggests the primary purpose is to direct users to a link farm, likely for SEO manipulation or to serve as a distribution point for further malicious content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092097095094097/Miracle-by-Elizabeth-Scott.pdf
    • http://loaminoo.linkpc.net/3095095099094091/Wrong-Beach-Island-Meg-Daniels-3-by-Jane-Kelly.pdf
    • http://loaminoo.linkpc.net/2093097099098099/Breakthrough-Elizabeth-Hughes-the-Discovery-of-Insulin-and-the-Making-of-a-Medical-Miracle-by-Thea-Cooper.pdf
    • http://loaminoo.linkpc.net/2090093090097090/The-Maverick-s-Greek-Island-Mistress-Bennett-3-by-Kelly-Hunter.pdf
    • http://loaminoo.linkpc.net/4091096092096097/The-Memory-Code-The-Secrets-of-Stonehenge-Easter-Island-and-Other-Ancient-Monuments-by-Lynne-Kelly.pdf
    • http://loaminoo.linkpc.net/3096096099097095/Notice-Me-Monhegan-Moonlight-Trilogy-Book-1-by-Lili-Lam.pdf
    • http://loaminoo.linkpc.net/4099092094092094/Healing-Gabriel-by-Elizabeth-Kelly.pdf
    • http://loaminoo.linkpc.net/2091097098097099/The-Last-Summer-of-the-Camperdowns-by-Elizabeth-Kelly.pdf
    • http://loaminoo.linkpc.net/1093098090096092/Jade-Island-Donovan-2-by-Elizabeth-Lowell.pdf
    • http://loaminoo.linkpc.net/4095096090098090/Inappropriate-Bristol-Island-2-by-Elizabeth-Finn.pdf
    • http://loaminoo.linkpc.net/1090090090099099092/When-we-meet-a-person-of-destiny-a-miracle-happens-in-my-life-A-trajectory-to-a-miracle-meeting-Twin-Soul-by-Manami-Himekawa.pdf
    • http://loaminoo.linkpc.net/7096095097092096/Stardust-Miracle-Miracle-Interrupted-2-by-Edie-Ramer.pdf
    • http://loaminoo.linkpc.net/2091091091090099/Whidbey-Island-Reflections-on-People-amp-the-Land-by-Elizabeth-Guss.pdf
    • http://loaminoo.linkpc.net/1097095096094092/The-Edge-of-the-Light-Whidbey-Island-Saga-4-by-Elizabeth-George.pdf
    • http://loaminoo.linkpc.net/5095097093097094/Christmas-Miracle-in-July-Christmas-Miracle-Series-Book-1-by-R-M-Gauthier.pdf
    • http://loaminoo.linkpc.net/1099096092093094/The-Recruit-Book-One-The-Recruit-1-by-Elizabeth-Kelly.pdf
    • http://loaminoo.linkpc.net/3098096090096097/The-Miracle-Girls-Miracle-Girls-1-by-Anne-Dayton.pdf
    • http://loaminoo.linkpc.net/2095096092093098/The-Temptation-of-Elizabeth-Tudor-Elizabeth-I-Thomas-Seymour-and-the-Making-of-a-Virgin-Queen-by-Elizabeth-Norton.pdf
    • http://loaminoo.linkpc.net/3093098094094097/Island-Colonization-The-Origin-and-Development-of-Island-Communities-by-Ian-Thornton.pdf
    • http://loaminoo.linkpc.net/5090095099094099/I-is-for-Island-A-Prince-Edward-Island-Alphabet-by-Hugh-Macdonald.pdf