Malicious PDF — malware analysis report

Static analysis result for SHA-256 f520d81a1a186dbc…

MALICIOUS

PDF

20.1 KB Created: 2019-05-01 17:41:26 +01:00 Authoring application: mPDF 5.7
MD5: 5c0b8de664d988694b6565a09c341f8d SHA-1: ac14255eef2fff71fdcb798f2765f28d210c215d SHA-256: f520d81a1a186dbccb6fdaee0013cdce70ffb0cb910e34627f35cae7a5a67efd
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious payloads. While the document body is heavily obfuscated, the presence of numerous links to external PDFs strongly suggests a malicious intent, likely to redirect users to potentially harmful content or to artificially inflate search engine rankings. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.l
    • http://loaminoo.linkpc.net/7096097091094096/Feminist-Narrative-Research-Opportunities-and-Challenges-by-Jo-Woodiwiss.pdf
    • http://loaminoo.linkpc.net/1091099095091097098/Feminist-Methods-in-Social-Research-by-Shulamit-Reinharz.pdf
    • http://loaminoo.linkpc.net/9095093093093095/Feminist-Research-Prospect-and-Retrospect-by-Peta-Tancred-Sheriff.pdf
    • http://loaminoo.linkpc.net/1091096098096090093/The-Farnham-Papers-1-by-Mary-Frances-Farnham.pdf
    • http://loaminoo.linkpc.net/1092090097091095/After-Impact-After-Impact-1-by-Nicole-Stark.pdf
    • http://loaminoo.linkpc.net/7096092091091097/Clues-to-Christie-The-Definitive-Guide-to-Miss-Marple-Hercule-Poirot-Tommy-amp-Tuppence-and-All-of-Agatha-Christie-s-Mysteries-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/2097090098093/The-Complete-Christie-An-Agatha-Christie-Encyclopedia-by-Matthew-Bunson.pdf
    • http://loaminoo.linkpc.net/1091098096090095091/The-Umbrella-Academy-Suite-Apocaliptica-Segundo-Acto-Umbrella-Academy-edici-n-r-stica-2-by-Gerard-Way.pdf
    • http://loaminoo.linkpc.net/1090096091097094096/Bad-Wicked-Twisted-A-Briarwood-Academy-Box-Set-Briarwood-Academy-1-3-by-Ilsa-Madden-Mills.pdf
    • http://loaminoo.linkpc.net/1091093094098099091/Flavour-Research-of-Alcoholic-Beverages-Instrumental-and-Sensory-Analysis-Proceedings-of-the-Alko-Symposium-on-Flavour-Research-of-Alcoholic-Beverag-by-Lalli-Nykanen.pdf
    • http://loaminoo.linkpc.net/1094095096098094/Don-t-Call-Me-Kit-Kat-by-K-J-Farnham.pdf
    • http://loaminoo.linkpc.net/7091091097096098/De-verfilmde-bestsellers-van-Agatha-Christie-Moord-in-de-Ori-nt-Expres-De-moordenaar-waagt-een-gok-Drama-in-drie-bedrijven-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/1091096098097091095/Way-Of-Jesus-by-Bruce-Farnham.pdf
    • http://loaminoo.linkpc.net/2095093097091093/A-Case-of-Serendipity-by-K-J-Farnham.pdf
    • http://loaminoo.linkpc.net/9091099093098090/Ponce-Academy-Die-Neue-Ponce-Academy-by-Barbara-Laban.pdf
    • http://loaminoo.linkpc.net/7099091093094095/The-Mysterious-Affair-at-Styles-by-Agatha-Christie-Annotated-James-Lynn-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/1091096098096090095/Farnham-in-War-and-Peace-by-W-Ewbank-Smith.pdf
    • http://loaminoo.linkpc.net/1091096098096095090/The-Exhausted-Dead-by-F-Allen-Farnham.pdf
    • http://loaminoo.linkpc.net/1091096098094099091/Farnham-Past-by-Jean-Parratt.pdf
    • http://loaminoo.linkpc.net/1091096098095095099/A-Crowd-of-Twisted-Things-by-Dawn-Farnham.pdf