Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe928481b838a61d…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 03:36:13 +01:00 Authoring application: mPDF 5.7
MD5: 5841c4d6de6a7ce9ba15b204e6b2e713 SHA-1: 96be98c9ca2f027a215b3e0173a8ae1d6555ae69 SHA-256: fe928481b838a61d7d7c7e30d0dd5d7c66e84a60781f2a89282815dbfad13e2e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. These links appear to be part of a link farm designed to direct users to various academic-looking documents hosted on the 'linkpc.net' domain. No scripts were extracted from this sample. The primary IOCs are the URLs associated with the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091090099099090095/History-And-The-Theology-Of-Liberation-A-Latin-American-Perspective-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091090099098095095/A-History-of-the-Church-in-Latin-America-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091091090092094094/Liberation-Method-and-Dialogue-Enrique-Dussel-and-North-American-Theological-Discourse-by-Roberto-S-Goizueta.pdf
    • http://loaminoo.linkpc.net/1091090099098094099/Philosophy-of-Liberation-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/9091092092099099/Systematic-Theology-Perpspectives-from-Liberation-Theology-Readings-from-Mysterium-Liberationis-by-Jon-Sobrino.pdf
    • http://loaminoo.linkpc.net/8094094093095092/Twenty-Theses-on-Politics-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091091090092093090/Church-at-Prayer-I-Sources-Liturgy-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091090099098095097/Towards-an-Unknown-Marx-A-Commentary-on-the-Manuscripts-of-1861-63-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091091090092094095/Befreiungstheologie-Und-Transzendentaltheologie-Enrique-Dussel-Und-Karl-Rahner-Im-Vergleich-by-Anton-Peter.pdf
    • http://loaminoo.linkpc.net/1091091090092093099/Pensar-Globalmente-y-Actuar-Regionalmente-Hacia-Un-Nuevo-Paradigma-Industrial-Para-El-Siglo-XXI-by-Enrique-Dussel-Peters.pdf
    • http://loaminoo.linkpc.net/1091090099098095094/The-Invention-of-the-Americas-Eclipse-of-quot-The-Other-quot-and-the-Myth-of-Modernity-by-Enrique-Dussel.pdf
    • http://loaminoo.linkpc.net/1091092092099093090/Introducing-Black-Theology-of-Liberation-by-Orbis.pdf
    • http://loaminoo.linkpc.net/1091093098097095094/Practical-Theology-of-Liberation-by-Hugo-Assmann.pdf
    • http://loaminoo.linkpc.net/1090090093099096092/Lessons-in-Liberation-The-Church-in-Latin-America-by-Peadar-Kirby.pdf
    • http://loaminoo.linkpc.net/7093090095091098/History-of-Franciscan-Theology-Theology-Series-by-Kenan-Osborne.pdf
    • http://loaminoo.linkpc.net/3091091092098090/Liberation-Theology-for-Armchair-Theologians-by-Miguel-A-de-la-Torre.pdf
    • http://loaminoo.linkpc.net/9091092092099098/Mysterium-Liberations-Fundamental-Concepts-of-Liberation-Theology-by-Orbis.pdf
    • http://loaminoo.linkpc.net/9091092092093096/Mysterium-Liberationis-Fundamental-Concepts-of-Liberation-Theology-by-Ignacio-Ellacur-a.pdf
    • http://loaminoo.linkpc.net/1091095092091095099/Early-Latin-theology-Selections-from-Tertullian-Cyprian-Ambrose-and-Jerome-by-S-L-Greenslade.pdf
    • http://loaminoo.linkpc.net/5094092090097092/Church-Charism-and-Power-Liberation-Theology-and-the-Institutional-Church-by-Leonardo-Boff.pdf
    • http://loaminoo.linkpc.net/1091090099098095