Malicious PDF — malware analysis report

Static analysis result for SHA-256 facc958fb3871e65…

MALICIOUS

PDF

18.2 KB Created: 2019-05-05 16:30:29 +01:00 Authoring application: mPDF 5.7
MD5: 670a35de9dc74b8f86d40858740170ec SHA-1: a99b1330dea44ffbadc3b0fb59b245217ce3839a SHA-256: facc958fb3871e65c623e74954f6704ef9e2d9f8a3ce3b38d0a0b31b6dca4c8d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. ClamAV detection as Pdf.Dropper.Agent-7178643-0 further supports its malicious nature. The embedded URLs are likely part of a link farm designed to artificially boost search engine rankings or redirect users to potentially harmful sites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7178643-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7178643-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1098093094095/The-Sacred-Balance-Rediscovering-Our-Place-in-Nature-by-David-Suzuki.pdf
    • http://loaminoo.linkpc.net/3090095091092094/David-Suzuki-s-Green-Guide-by-David-Suzuki.pdf
    • http://loaminoo.linkpc.net/3099091092092099/A-Place-Within-Rediscovering-India-by-M-G-Vassanji.pdf
    • http://loaminoo.linkpc.net/1090093096097097/Our-Sacred-Balance-Triquetra-3-by-Marguerite-Labbe.pdf
    • http://loaminoo.linkpc.net/3095096090097095/The-Weather-Detective-Rediscovering-Nature-s-Secret-Signs-by-Peter-Wohlleben.pdf
    • http://loaminoo.linkpc.net/4093097094094098/David-Suzuki-The-Autobiography-by-David-Suzuki.pdf
    • http://loaminoo.linkpc.net/1091095092096095098/EcoCities-Rebuilding-Cities-in-Balance-with-Nature-by-Richard-Register.pdf
    • http://loaminoo.linkpc.net/9094093099099096/Suzuki-Piano-School--New-International-Edition--Book-1--Book-amp-CD-Suzuki-Method-Core-Materials-by-Shinichi-Suzuki.pdf
    • http://loaminoo.linkpc.net/7095097092095098/The-Toronto-Carrying-Place-Rediscovering-Toronto-s-Most-Ancient-Trail-by-Glenn-Turner.pdf
    • http://loaminoo.linkpc.net/3092097099096093/Along-the-Wheel-of-Time-Sacred-Stories-for-Nature-Lovers-by-Judith-Laxer.pdf
    • http://loaminoo.linkpc.net/1093098096096097/A-Poet-s-Bible-Rediscovering-the-Voices-of-the-Original-Text-by-David-Rosenberg.pdf
    • http://loaminoo.linkpc.net/9094094092098098/Suzuki-Cello-School-Volumes-1-and-2-Audio-CD-by-Shinichi-Suzuki.pdf
    • http://loaminoo.linkpc.net/5090098099096/The-Nature-of-the-Place-A-Study-of-Great-Plains-Fiction-by-Diane-Dufva-Quantic.pdf
    • http://loaminoo.linkpc.net/4099094097097091/Wildbranch-An-Anthology-of-Nature-Environmental-and-Place-based-Writing-by-Florence-Caplow.pdf
    • http://loaminoo.linkpc.net/5094090090095/Written-in-Stone-Evolution-the-Fossil-Record-and-Our-Place-in-Nature-by-Brian-Switek.pdf
    • http://loaminoo.linkpc.net/9094093099098098/Dr-Shinichi-Suzuki-Teaching-Music-from-the-Heart-by-David-R-Collins.pdf
    • http://loaminoo.linkpc.net/9094094090094098/Suzuki-Piano-School-Vol-2-by-Shinichi-Suzuki.pdf
    • http://loaminoo.linkpc.net/9094094092090091/Suzuki-Piano-School-Vol-3-by-Shinichi-Suzuki.pdf
    • http://loaminoo.linkpc.net/8094090094096093/Creating-Balance-A-Self-Reflective-Book-to-Bring-More-Energy-Productivity-and-Balance-into-Your-Life-by-Alene-Baronian-MS-RDN.pdf
    • http://loaminoo.linkpc.net/3092091090099091/balance-your-chakras-balance-your-life-by-Becca-Chopra.pdf