Malicious PDF — malware analysis report

Static analysis result for SHA-256 249a63bae1b8e51f…

MALICIOUS

PDF

15.5 KB Created: 2019-04-29 23:28:43 +01:00 Authoring application: mPDF 5.7
MD5: 6ca5066aef5e1f666830a1b9d3dfa2f6 SHA-1: 099cef3848183c8da06cc29f4e8e431c05938984 SHA-256: 249a63bae1b8e51feb179093e7b25d33ccbf0b30d744dafbb3173997ac5c6ebd
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic firing indicates this is a SEO link farm, suggesting the intent is to drive traffic to these external sites. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to manipulate search engine results or direct users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097097092094098/Shadows-of-Doubt-A-Series-of-Shadows-1-by-Mell-Corcoran.pdf
    • http://loaminoo.linkpc.net/5098097093095098/Moonlit-Shadows-Taken-Moonlit-Shadows-Series-Book-1-by-Shawna-Gautier.pdf
    • http://loaminoo.linkpc.net/2094091099091097/The-Shadows-The-Return-Has-Begun-The-Shadows-Saga-1-by-Alouy-Martinez.pdf
    • http://loaminoo.linkpc.net/4098095095099/Out-of-the-Shadows-Bishop-Special-Crimes-Unit-3-Shadows-3-by-Kay-Hooper.pdf
    • http://loaminoo.linkpc.net/4099098093097/Shadows-Gray-Shadows-1-by-Melyssa-Williams.pdf
    • http://loaminoo.linkpc.net/1090097096094095/Shadows-Shadows-1-by-Cheree-Alsop.pdf
    • http://loaminoo.linkpc.net/2099097091099090/Shadows-of-Yesterday-Ravenhurst-Series-2-by-Lorraine-Beaumont.pdf
    • http://loaminoo.linkpc.net/1091098092094093091/Living-in-the-Shadows-The-Foundling-s-Path---Part-1-Linmore-Series-Book-4-by-Jemima-Brigges.pdf
    • http://loaminoo.linkpc.net/6097099093097/Golden-Shadows-Shadows-Golden-Under-the-Sun-by-Amitava-Mazumdar.pdf
    • http://loaminoo.linkpc.net/6094096095/Mask-of-Shadows-Mask-of-Shadows-1-by-Linsey-Miller.pdf
    • http://loaminoo.linkpc.net/3098095091094091/Dreams-and-Shadows-Dreams-amp-Shadows-1-by-C-Robert-Cargill.pdf
    • http://loaminoo.linkpc.net/6098092095094/Dance-of-Shadows-Dance-of-Shadows-1-by-Yelena-Black.pdf
    • http://loaminoo.linkpc.net/6092098092/Mask-of-Shadows-Mask-of-Shadows-1-by-Linsey-Miller.pdf
    • http://loaminoo.linkpc.net/4098093099093097/Castle-of-Shadows-Castle-of-Shadows-1-by-Ellen-Renner.pdf
    • http://loaminoo.linkpc.net/5092099092090/Dreams-and-Shadows-Dreams-amp-Shadows-1-by-C-Robert-Cargill.pdf
    • http://loaminoo.linkpc.net/9097099098096/Rising-Shadows-Rising-Shadows-1-by-Ashley-Townsend.pdf
    • http://loaminoo.linkpc.net/2093095097094093/Circle-of-Shadows-Circle-of-Shadows-1-by-Evelyn-Skye.pdf
    • http://loaminoo.linkpc.net/1092097096091094/Reasonable-Doubt-Full-Series-Reasonable-Doubt-1-3-25-by-Whitney-G-.pdf
    • http://loaminoo.linkpc.net/2096090090096/Shadows-amp-Tall-Trees-Shadows-amp-Tall-Trees-6-by-Michael-Kelly.pdf
    • http://loaminoo.linkpc.net/5098099094099/Beyond-a-Doubt-Rock-Harbor-Series-2-by-Colleen-Coble.pdf
    • http://loaminoo.linkpc.net/6097099093097