Malicious PDF — malware analysis report

Static analysis result for SHA-256 204d4fe19878eb38…

MALICIOUS

PDF

22.5 KB Created: 2019-04-30 18:22:14 +01:00 Authoring application: mPDF 5.7
MD5: 74ec24a24d6f01b7bdc29b5d4dcea0ce SHA-1: ddfc6b14a0a65731a4b6be715e67f1c9013be010 SHA-256: 204d4fe19878eb3870e39d894b8f8c60144f4611e190e0360dbb3c1e553fec73
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, suggesting a link farm or content aggregation tactic. The heuristic 'PDF_SEO_LINK_FARM' indicates a high volume of numeric slugs in the URLs, pointing towards an attempt to generate traffic or distribute content through SEO manipulation. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099098091094099/Razor-s-Edge-Star-Wars-Empire-and-Rebellion-1-by-Martha-Wells.pdf
    • http://loaminoo.linkpc.net/9090093094093099/Rebellion-The-Galactic-Empire-Wars-3-by-Raymond-L-Weil.pdf
    • http://loaminoo.linkpc.net/6099091094091098/Crimson-Empire-Volume-1-Star-Wars-Crimson-Empire-1-by-Mike-Richardson.pdf
    • http://loaminoo.linkpc.net/5093099092091091/Star-Wars-Heir-to-the-Empire-by-Timothy-Zahn.pdf
    • http://loaminoo.linkpc.net/3093099093093092/Conquest-Edge-of-Victory-1-Star-Wars-The-New-Jedi-Order-7-by-Greg-Keyes.pdf
    • http://loaminoo.linkpc.net/3094090090099090/Star-Wars-Infinities---The-Empire-Strikes-Back-by-Dave-Land.pdf
    • http://loaminoo.linkpc.net/9099092095094091/Star-Wars-Empire-Volume-3-The-Imperial-Perspective-by-Paul-Alden.pdf
    • http://loaminoo.linkpc.net/3093099097094091/The-Art-of-Star-Wars-Episode-V-The-Empire-Strikes-Back-by-Deborah-Call.pdf
    • http://loaminoo.linkpc.net/3093099097093091/Star-Wars-The-Empire-Strikes-Back---The-Special-Edition-by-Archie-Goodwin.pdf
    • http://loaminoo.linkpc.net/9094096092092092/Star-Wars-The-Empire-Strikes-Back-Manga-Volume-1-by-Toshiki-Kudo.pdf
    • http://loaminoo.linkpc.net/9094096092092091/Star-Wars-The-Empire-Strikes-Back-Manga-Volume-4-by-Toshiki-Kudo.pdf
    • http://loaminoo.linkpc.net/6096091097091096/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T07-La-Destructrice-Star-Wars-Knights-of-the-Old-Republic-8-by-John-Jackson-Miller.pdf
    • http://loaminoo.linkpc.net/6096091097091093/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T08-D-mon-Star-Wars-Knights-of-the-Old-Republic-9-by-John-Jackson-Miller.pdf
    • http://loaminoo.linkpc.net/9096098098097093/Star-Wars-Das-Imperium-schl-gt-zur-ck---Du-willst-also-ein-Jedi-werden-Star-Wars-Illustrated-Novels-2-by-Adam-Gidwitz.pdf
    • http://loaminoo.linkpc.net/6096091096098096/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T05-Sans-piti-Star-Wars-Knights-of-the-Old-Republic-6-by-John-Jackson-Miller.pdf
    • http://loaminoo.linkpc.net/6096091096096095/Star-Wars-Chevaliers-de-l-ancienne-r-publique-T02-Ultime-recours-Star-Wars-Knights-of-the-Old-Republic-2-by-John-Jackson-Miller.pdf
    • http://loaminoo.linkpc.net/1090094090097093090/Legenden-om-Star-Wars-Imperiets-Arvinge-Star-Wars-The-Thrawn-Trilogy-1-by-Timothy-Zahn.pdf
    • http://loaminoo.linkpc.net/3093099097096090/Star-Wars-Episode-III-Revenge-of-the-Sith-Star-Wars-Novelizations-3-by-Matthew-Woodring-Stover.pdf
    • http://loaminoo.linkpc.net/3099099098096092/Star-Wars-Wisdom-Star-wars-Inspirational-Quotes-from-Yoda-Obi-wan-and-others-by-ZACH-ABRAHAM.pdf
    • http://loaminoo.linkpc.net/3093099097091090/Star-Wars-Vol-2-Showdown-on-the-Smuggler-s-Moon-Star-Wars-2-by-Jason-Aaron.pdf