Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcd06f97fef38dd4…

MALICIOUS

PDF

14.4 KB Created: 2019-04-30 18:35:31 +01:00 Authoring application: mPDF 5.7
MD5: 8b27a8071fefa4779b032e861b79e82a SHA-1: 4477f415c7255464d8aff2e759d4bc136f84914d SHA-256: fcd06f97fef38dd4b05246c27314c267d2c2e7dd2ace20518ec8b14b39d8a38f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, with the dominant host being 'loaminoo.linkpc.net'. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to drive traffic or potentially host further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090095091099096097/Z-rich-by-Mike-12-by-Mike-van-Audenhove.pdf
    • http://loaminoo.linkpc.net/1090095091098099091/Z-rich-By-Mike-Bd-11-by-Mike-van-Audenhove.pdf
    • http://loaminoo.linkpc.net/3094092093094090/Mike-and-Dave-Need-Wedding-Dates-And-a-Thousand-Cocktails-by-Mike-Stangle.pdf
    • http://loaminoo.linkpc.net/2093098092095097/Bayou-Farewell-The-Rich-Life-and-Tragic-Death-of-Louisiana-s-Cajun-Coast-by-Mike-Tidwell.pdf
    • http://loaminoo.linkpc.net/3093099097090/Mrs-Mike-Mrs-Mike-1-by-Benedict-Freedman.pdf
    • http://loaminoo.linkpc.net/1093090092094097/The-Blue-Flames-that-Keep-Us-Warm-Mike-McCardell-s-Favourite-Stories-by-Mike-McCardell.pdf
    • http://loaminoo.linkpc.net/6092093096090095/Mike-McGrath-s-Book-of-Compost-by-Mike-McGrath.pdf
    • http://loaminoo.linkpc.net/2099096093092099/Miracle-Boy-Mike-Reilly-by-Mike-Reilly.pdf
    • http://loaminoo.linkpc.net/5093094096094/Rich-Dad-s-Retire-Young-Retire-Rich-How-to-Get-Rich-Quickly-and-Stay-Rich-Forever-by-Robert-T-Kiyosaki.pdf
    • http://loaminoo.linkpc.net/7098092092/The-Man-I-Think-I-Know-by-Mike-Gayle.pdf
    • http://loaminoo.linkpc.net/1095091098097092/Dog-by-Mike-Robbins.pdf
    • http://loaminoo.linkpc.net/2094094095098096/QB-1-by-Mike-Lupica.pdf
    • http://loaminoo.linkpc.net/2090091094092090/Here-and-Now-and-Then-by-Mike-Chen.pdf
    • http://loaminoo.linkpc.net/2096090094096099/Better-by-Mike-Olley.pdf
    • http://loaminoo.linkpc.net/4096090092093/Dad-s-First-Day-by-Mike-Wohnoutka.pdf
    • http://loaminoo.linkpc.net/1091098098091099/Nothing-Down-by-Mike-Reuther.pdf
    • http://loaminoo.linkpc.net/5094099095098/The-Underdogs-by-Mike-Lupica.pdf
    • http://loaminoo.linkpc.net/8093095092090/All-Shook-Up-by-Mike-Harrison.pdf
    • http://loaminoo.linkpc.net/2099098094097/The-Unwritten-Vol-3-by-Mike-Carey.pdf
    • http://loaminoo.linkpc.net/8098091092099093/Always-Tomorrow-by-Mike-Tager.pdf