Malicious PDF — malware analysis report

Static analysis result for SHA-256 fef20710073baec4…

MALICIOUS

PDF

16.2 KB Created: 2019-05-05 16:30:52 +01:00 Authoring application: mPDF 5.7
MD5: 748e24af1cd61092705a58db1b428e4f SHA-1: caed5f4e72c5f2a5e64d0a66763b99b147e5b074 SHA-256: fef20710073baec48e9c6dd44335ae67c456defa79ac3f0cb164d884c5355f15
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, indicating a large number of embedded external URLs. While most of these URLs point to benign-looking book titles, the sheer volume and the nature of the heuristic suggest a potential for SEO manipulation or hosting of malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the direct intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093095094097098/Manny-Khoshbin-s-Contrarian-Playbook-How-to-Build-Your-100-Million-Real-Estate-Portfolio-from-the-Ground-Up-by-Manny-Khoshbin.pdf
    • http://loaminoo.linkpc.net/7093095092099091/Negative-Space-Manny-Farber-on-the-Movies-by-Manny-Farber.pdf
    • http://loaminoo.linkpc.net/2097098091094095/Daisy-s-Story-Daisy-s-Adventures-1-by-Margaret-O-39-Connor.pdf
    • http://loaminoo.linkpc.net/1098098096097093/Accidentally-Married-Married-1-by-Victorine-E-Lieske.pdf
    • http://loaminoo.linkpc.net/9093099099098092/Acting-Married-Married-5-by-Victorine-E-Lieske.pdf
    • http://loaminoo.linkpc.net/3096094099093096/Accidentally-Married-Married-1-by-Victorine-E-Lieske.pdf
    • http://loaminoo.linkpc.net/9093099099097099/Blissfully-Married-Married-4-by-Victorine-E-Lieske.pdf
    • http://loaminoo.linkpc.net/9093091098098093/Daisy-Daisy-Kitten-Fair-by-L-K-Merideth.pdf
    • http://loaminoo.linkpc.net/4094098096099096/Daisy-and-the-Pirates-Daisy-Tannenbaum-1-by-J-T-Allen.pdf
    • http://loaminoo.linkpc.net/1094098097098094/I-Married-a-Billionaire-Lost-amp-Found-I-Married-a-Billionaire-2-by-Melanie-Marchande.pdf
    • http://loaminoo.linkpc.net/1090091097097098091/Daisy-McDare-and-the-Deadly-Restaurant-Affair-Daisy-McDare-6-by-K-M-Morgan.pdf
    • http://loaminoo.linkpc.net/3090092095095099/Will-amp-Patrick-Wake-Up-Married-Wake-Up-Married-1-by-Leta-Blake.pdf
    • http://loaminoo.linkpc.net/4091099096090097/Manny-Get-Your-Guy-The-Mannies-2-by-Amy-Lane.pdf
    • http://loaminoo.linkpc.net/2093094094092096/The-Manny-by-Sara-Bell.pdf
    • http://loaminoo.linkpc.net/7093095094098094/Manny-s-Search-by-Edward-C-Burton.pdf
    • http://loaminoo.linkpc.net/2099097096096099/Dagboek-van-een-Manny-by-Holly-Peterson.pdf
    • http://loaminoo.linkpc.net/2093090092095090/The-Manny-Diaries-by-Kilt-Kilpatrick.pdf
    • http://loaminoo.linkpc.net/4094098096091095/And-Manny-Makes-Three-by-Trina-Solet.pdf
    • http://loaminoo.linkpc.net/3091093093090095/Baby-Daisy-s-Good-Idea-La-Buena-Idea-De-Bebe-Daisy-Baby-s-First-Disney-Books-English-Spanish-by-Walt-Disney-Company.pdf
    • http://loaminoo.linkpc.net/5091093099093/Outcry---Holocaust-memoirs-by-Manny-Steinberg.pdf
    • http://loaminoo.linkpc.net/1094098097098094/I-Marr