Malicious PDF — malware analysis report

Static analysis result for SHA-256 f60bf15fecf2331a…

MALICIOUS

PDF

20.9 KB Created: 2019-04-30 04:45:34 +01:00 Authoring application: mPDF 5.7
MD5: 6addc85ac32db21f8fc45e2b5f1fa13d SHA-1: a4c88a0ba2211e50ddffc6f8ca547e4f60d4044b SHA-256: f60bf15fecf2331a0e152c2825cd46e9bb884ecb84a9d49191fb6d9e9d1225ed
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was identified as malicious due to a critical heuristic firing for a large number of embedded external links. While most of these links were labeled as benign, the sheer volume suggests a malicious intent, possibly for SEO manipulation or to host further malicious content. No scripts were extracted, and the document body was heavily corrupted, preventing a deeper analysis of the content's purpose. The attack pattern is inferred from the PDF_SEO_LINK_FARM heuristic.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090092090095/The-School-Reform-Landscape-Fraud-Myth-and-Lies-by-Christopher-H-Tienken.pdf
    • http://loaminoo.linkpc.net/5097097099092097/Landscape-in-the-Longue-Dur-e-A-History-and-Theory-of-Pebbles-in-a-Pebbled-Heathland-Landscape-by-Christopher-Tilley.pdf
    • http://loaminoo.linkpc.net/8094090096095095/Christopher-Isherwood-Myth-and-Anti-Myth-by-Paul-Piazza.pdf
    • http://loaminoo.linkpc.net/7096091090092/North-Pole-Reform-School-by-Jaimie-Admans.pdf
    • http://loaminoo.linkpc.net/5091090095098090/Across-The-Mutual-Landscape-by-Christopher-Gilbert.pdf
    • http://loaminoo.linkpc.net/8095090096090091/A-Brush-With-Nature-The-Gere-Collection-of-Landscape-Oil-Sketches-Revised-Edition-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/8095090096090090/Forests-Rocks-Torrents-Norwegian-and-Swiss-Landscape-Paintings-from-the-Lunde-Collection-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/3094092095097092/IRONBARK-HILL-There-lies-ahead-a-long-rough-road-for-a-girl-fighting-discrimination-seeking-revenge-and-pursuing-a-career-in-landscape-painting-by-Jennie-Linnane.pdf
    • http://loaminoo.linkpc.net/2099090091097092/Where-My-Love-Lies-Dreaming-by-Christopher-Hawthorne-Moss.pdf
    • http://loaminoo.linkpc.net/2095098096095097/The-Unholy-Bible-Exposing-the-Lies-Your-Sunday-School-Teacher-Told-You-by-Nathan-Harris.pdf
    • http://loaminoo.linkpc.net/4090090091094092/The-School-of-Hard-Knocks-Schooled-in-Magic-5-by-Christopher-G-Nuttall.pdf
    • http://loaminoo.linkpc.net/1090098094098098/School-of-Deaths-The-Scythe-Wielder-s-Secret-1-by-Christopher-Mannino.pdf
    • http://loaminoo.linkpc.net/1090091090091090/American-Conspiracies-Lies-Lies-and-More-Dirty-Lies-that-the-Government-Tells-Us-by-Jesse-Ventura.pdf
    • http://loaminoo.linkpc.net/7099091093094093/Myth-Conceptions-Myth-Adventures-Book-2-by-Robert-Lynn-Asprin.pdf
    • http://loaminoo.linkpc.net/2097093092097091/Myth-ion-Improbable-Myth-Adventures-11-by-Robert-Lynn-Asprin.pdf
    • http://loaminoo.linkpc.net/2091091095091096/Tender-Secrets-Secrets-and-Lies-1-by-Ann-Christopher.pdf
    • http://loaminoo.linkpc.net/9099091095093093/Myth-and-the-Human-Sciences-Hans-Blumenberg-s-Theory-of-Myth-Hans-Blumenberg-s-Theory-of-Myth-by-Angus-Nicholls.pdf
    • http://loaminoo.linkpc.net/1094095095091092/Love-Lies-amp-High-Heels-Love-Lies-and-More-Lies-1-by-Debby-Conrad.pdf
    • http://loaminoo.linkpc.net/9095096093/FRAUD-by-R-C-Stephens.pdf
    • http://loaminoo.linkpc.net/1099091096090/Fraud-Essays-by-David-Rakoff.pdf