Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5aaa6c9af036d30…

MALICIOUS

PDF

15.9 KB Created: 2019-04-30 18:00:15 +01:00 Authoring application: mPDF 5.7
MD5: 3b24834dd5dba6d4d57054341f1abb29 SHA-1: 9b12979fde5927d4b719a24101b59bd3aac57af7 SHA-256: f5aaa6c9af036d30bd6984361b50b2dc79169767409c9a750566256b5258a2f2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or as a distribution vector for further malicious content. No scripts were extracted from this sample. The attack pattern is likely related to phishing or malicious redirection.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093099097098/The-Passion-of-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4095090095091092/Seeing-and-Savoring-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094090097090/Seeing-and-Savoring-Jesus-Christ-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094090096094091/Sanctification-in-the-Everyday-Three-Sermons-by-John-Piper-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4092098096092095/Who-Is-Jesus-Answers-to-Your-Questions-About-the-Historical-Jesus-by-John-Dominic-Crossan.pdf
    • http://loaminoo.linkpc.net/1090090090091097097/Lessons-from-a-Hospital-Bed-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/2096092097092093/Don-t-Waste-Your-Life-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/8092094096091/When-I-Don-t-Desire-God-How-to-Fight-for-Joy-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4092093099091092/Think-The-Life-of-the-Mind-and-the-Love-of-God-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/4094091099093094/The-Piper-at-the-Gates-of-Dawn-by-John-Cavanagh.pdf
    • http://loaminoo.linkpc.net/7097093096091092/Preparing-for-Marriage-Help-for-Christian-Couples-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6091097099098/God-Is-the-Gospel-Meditations-on-God-s-Love-as-the-Gift-of-Himself-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6097092094092/Desiring-God-Meditations-of-a-Christian-Hedonist-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/6094092099094098/Five-Points-Towards-a-Deeper-Experience-of-God-s-Grace-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/7092098090090095/The-Pied-Piper-of-Hamelin-A-German-Folktale-by-Amanda-St-John.pdf
    • http://loaminoo.linkpc.net/4099099097092097/An-Introduction-to-What-s-the-Difference-Manhood-and-Womanhood-Defined-According-to-the-Bible-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/1091093097092090096/The-Dog-of-Jesus-The-dog-that-changed-the-world-by-Michael-P-Sakowski.pdf
    • http://loaminoo.linkpc.net/1091092092091090092/Jesus-in-the-Jewish-World-by-G-za-Verm-s.pdf
    • http://loaminoo.linkpc.net/7091090093098097/Glocalization-How-Followers-of-Jesus-Engage-a-Flat-World-by-Bob-Roberts-Jr-.pdf
    • http://loaminoo.linkpc.net/1090097097093094094/The-Light-of-the-World-The-Life-and-Teachings-of-Jesus-of-Nazareth-by-Tim-Spiess.pdf
    • http://loaminoo.linkpc.net/6091097099098/God-Is-the-Gospel-Meditations-on-God-s-Love-as-the-Gift