Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6ae2c3794b8b371…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 04:33:23 +01:00 Authoring application: mPDF 5.7
MD5: 69cb08aed75f1f45e58b747d114eef65 SHA-1: 06ca24103bfbb2dcb7be4aa9af152e752f6595b6 SHA-256: f6ae2c3794b8b37161bd55bc20be7694a66a6b8c0ec9ed4d946417a14555c5f1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. No scripts were extracted, and the document body was unreadable, limiting further analysis.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094099096090091/Extraordinary-Leadership-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/5094099094091096/The-Robin-Sharma-Pack-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/1092097095099093/The-Monk-Who-Sold-His-Ferrari-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/6094092092091090/The-Secret-Letters-of-the-Monk-Who-Sold-His-Ferrari-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/5090093092099/Family-Wisdom-from-the-Monk-Who-Sold-His-Ferrari-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/5094099095096091/Daily-Inspiration-from-The-Monk-Who-Sold-His-Ferrari-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/5094099094096097/Discover-Your-Destiny-with-The-Monk-Who-Sold-His-Ferrari-The-7-Stages-of-Self-Awakening-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/6090095096097098/Le-moine-qui-vendit-sa-Ferrari-Une-fable-spirituelle-pour-r-aliser-vos-r-ves-et-accomplir-votre-destin-e-by-Robin-S-Sharma.pdf
    • http://loaminoo.linkpc.net/7095093091093090/Leadership-the-Eleanor-Roosevelt-Way-Timeless-Strategies-from-the-First-Lady-of-Courage-by-Robin-Gerber.pdf
    • http://loaminoo.linkpc.net/1090091095093095/Leadership-Mosaic-5-Leadership-Principles-for-Ministry-and-Everyday-Life-by-Daniel-Montgomery.pdf
    • http://loaminoo.linkpc.net/4099098090099090/Leadership-and-the-One-Minute-Manager-Increasing-Effectiveness-Through-Situational-Leadership-by-Kenneth-H-Blanchard.pdf
    • http://loaminoo.linkpc.net/1090093090092091/The-Toyota-Way-to-Lean-Leadership-Achieving-and-Sustaining-Excellence-Through-Leadership-Development-by-Jeffrey-K-Liker.pdf
    • http://loaminoo.linkpc.net/4096093091092092/Leadership-Reflections-on-Biblical-Leadership-Today-by-Philip-Greenslade.pdf
    • http://loaminoo.linkpc.net/8090096091092096/Anything-But-Extraordinary-Extraordinary-1-by-Mary-Frame.pdf
    • http://loaminoo.linkpc.net/1090097092097097092/Robin-Wayeldt-Ein-schreckliches-Erbe-Robin-Wayeldt-Krimi-2-by-Robin-Wayeldt.pdf
    • http://loaminoo.linkpc.net/5094099095096098/Principles-of-Pharmacology-by-H-L-Sharma.pdf
    • http://loaminoo.linkpc.net/6096094093099090/The-Ramayana-by-Bulbul-Sharma.pdf
    • http://loaminoo.linkpc.net/4095098094099090/All-Eyes-on-Her-by-Poonam-Sharma.pdf
    • http://loaminoo.linkpc.net/2092092091098097/The-Pancatantra-by-Vishnu-Sharma.pdf
    • http://loaminoo.linkpc.net/3099093098098090/Ravenvale-by-Isha-Sharma.pdf
    • http://loaminoo.linkpc.net/6090095096097098/Le-moine-qui-vendit-sa-Ferrari-Une-fable-spirituelle-pour-r-alise