Malicious PDF — malware analysis report

Static analysis result for SHA-256 f63fcad9fdabbd64…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 17:23:09 +01:00 Authoring application: mPDF 5.7
MD5: 7b37a13674569e053735cf2a28b6ed65 SHA-1: f22ab87d8b01bb13b195056d232ad6ece3ad247b SHA-256: f63fcad9fdabbd640a5e3402b6368c3505545a76c8090cbf9bb8da4d4180dddc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, limiting the ability to determine a specific payload delivery mechanism.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094091099/The-Ex-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/4098097096095095/Never-Tell-Ellie-Hatcher-4-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/2093091092097090/Angel-s-Tip-Ellie-Hatcher-2-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/4098094099094091/Missing-Justice-Samantha-Kincaid-2-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/6091094094098097/Dead-Connection-Ellie-Hatcher-1-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/4098097096093096/Missing-Justice-Samantha-Kincaid-2-by-Alafair-Burke.pdf
    • http://loaminoo.linkpc.net/3094096094098096/Nine-letters-long-by-J-C-Burke.pdf
    • http://loaminoo.linkpc.net/4095090096095092/That-Burke-Man-Long-Tall-Texans-12-by-Diana-Palmer.pdf
    • http://loaminoo.linkpc.net/6091094094095093/Burke-s-Gamble-Burke-2-by-William-F-Brown.pdf
    • http://loaminoo.linkpc.net/2097093098093092/Hornswoggled-Alafair-Tucker-2-by-Donis-Casey.pdf
    • http://loaminoo.linkpc.net/7095095092097094/James-Lee-Burke-A-Dave-Robicheaux-Audio-Collection-A-Stained-White-Radiance-In-The-Electric-Mist-With-Confederate-Dead-Dixie-City-Jam-Burning-Angel-and-Cadillac-Jukebox-by-James-Lee-Burke.pdf
    • http://loaminoo.linkpc.net/2096098098090093/The-Old-Buzzard-Had-It-Coming-Alafair-Tucker-1-by-Donis-Casey.pdf
    • http://loaminoo.linkpc.net/2097099098094098/Crying-Blood-Alafair-Tucker-5-by-Donis-Casey.pdf
    • http://loaminoo.linkpc.net/1098099099098/My-Awesome-Place-Autobiography-of-Cheryl-Burke-by-Cheryl-Burke.pdf
    • http://loaminoo.linkpc.net/5099096095092/A-Long-Long-Time-Ago-and-Essentially-True-by-Brigid-Pasulka.pdf
    • http://loaminoo.linkpc.net/7095095093098091/JAMES-LEE-BURKE-BOOKS-AND-ALL-SHORT-STORIES-CHECKLIST-AND-SUMMARIES---INCLUDES-LATEST-DAVE-ROBICHEAUX---JAMES-LEE-BURKE-SHORT-STORIES-AND-STANDALONE-NOVELS-AND-CHECKLIST-BEST-READING-ORDER-Book-56-by-Avid-Reader.pdf
    • http://loaminoo.linkpc.net/7097099090094/A-Long-Long-Sleep-UniCorp-1-by-Anna-Sheehan.pdf
    • http://loaminoo.linkpc.net/1090092095090097/Litany-of-the-Long-Sun-The-Book-of-the-Long-Sun-1-2-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/3092094090090092/The-Long-Utopia-The-Long-Earth-4-by-Terry-Pratchett.pdf
    • http://loaminoo.linkpc.net/5094096097099/Exodus-from-the-Long-Sun-The-Book-of-the-Long-Sun-4-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/7095095092097094/James-Lee-