Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5a6cdbc44ebf9b0…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 05:40:41 +01:00 Authoring application: mPDF 5.7
MD5: 692ed9ec1f6d7287e6afb624d997fe20 SHA-1: fbe55d7c71e91803ecd63504c3aa70f20bf7de3b SHA-256: f5a6cdbc44ebf9b0494794e84b6565e9bd1913d8924c7cbdede696f314ea45ec
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to serve as a lure for further malicious activity. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific payload.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/9091092099099095/Status-and-Understanding-of-Groundwater-Quality-in-the-South-Coast-Range-Coastal-Study-Unit-2008-California-Gama-Priority-Basin-Project-by-Carmen-A-Burton.pdf
    • http://loaminoo.linkpc.net/2099092092098/Stranger-in-Thunder-Basin-by-John-D-Nesbitt.pdf
    • http://loaminoo.linkpc.net/1090092096094092/Oranges-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/1098097099098093/The-Control-of-Nature-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/1093097090097093/Encounters-with-the-Archdruid-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/2091094099096095/The-Control-of-Nature-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/3090094093095092/The-Deltoid-Pumpkin-Seed-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/4092093092091097/Giving-Good-Weight-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/3090094090094093/A-Sense-of-Where-You-Are-Bill-Bradley-at-Princeton-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/4097097094094/Range-of-Glaciers-The-Exploration-and-Survey-of-the-Northern-Cascade-Range-by-Fred-Beckey.pdf
    • http://loaminoo.linkpc.net/2097098090098097/An-Unsettled-Range-Range-3-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2096094090090098/A-Shared-Range-Range-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4095097090092091/An-Isolated-Range-Range-5-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4092092094092092/A-Foreign-Range-Range-4-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/1095095096098/The-Curve-of-Binding-Energy-A-Journey-Into-the-Awesome-and-Alarming-World-of-Theodore-B-Taylor-by-John-McPhee.pdf
    • http://loaminoo.linkpc.net/5093090092099092/Alaska-s-Brooks-Range-The-Ultimate-Mountains-by-John-Kauffmann.pdf
    • http://loaminoo.linkpc.net/9097094098093097/World-s-Greatest-Sleuth-A-Holmes-on-the-Range-Mystery-Holmes-on-the-Range-Mysteries-Volume-5-by-Steve-Hockensmith.pdf
    • http://loaminoo.linkpc.net/8097095094099096/The-Aral-Sea-Basin-by-Philip-P-Micklin.pdf
    • http://loaminoo.linkpc.net/1090097090097092093/Oil-Exploration-Basin-Analysis-and-Economics-by-Ian-Lerche.pdf
    • http://loaminoo.linkpc.net/5092090094097092/Ba-n-ne-E-ilmesin-Sabahattin-Ali-nin-Roman-by-H-fz-Topuz.pdf