Malicious PDF — malware analysis report

Static analysis result for SHA-256 282118f6084567cc…

MALICIOUS

PDF

20.1 KB Created: 2019-05-04 13:56:32 +01:00 Authoring application: mPDF 5.7
MD5: 68bc38d6793235d42b96b9662d3f01dc SHA-1: 8e55c6990ff23b0a8634d3699947338c173a85a3 SHA-256: 282118f6084567cc8c0e16fc4adb1c3b849650a2d43df5d68f2e07ccc7618a6f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090095090090097/Fort-Lewis-by-Alan-H-Archambault.pdf
    • http://loaminoo.linkpc.net/6093092097091099/Fort-Duquesne-and-Fort-Pitt-by-Daughters-of-the-American-Revolution.pdf
    • http://loaminoo.linkpc.net/6093092097092091/Fort-Duquesne-and-Fort-Pitt-by-Of-the-American-Revolution-Pennsylvania.pdf
    • http://loaminoo.linkpc.net/6093093091093092/Bourland-in-North-Texas-and-Indian-Territory-During-the-Civil-War-Fort-Cobb-Fort-Arbuckle-amp-the-Wichita-Mountains-Volume-II-Appendix-by-Patricia-Adkins-Rochette.pdf
    • http://loaminoo.linkpc.net/7096095098093094/Lewis-and-Clark-Trail-Maps-Missouri-River-Between-Camp-River-DuBois-Illinois-and-Fort-Mandan-North-Dakota--Outbound-1804-Return-1806-by-Martin-Plamondon.pdf
    • http://loaminoo.linkpc.net/1092099098098098/The-Narnian-The-Life-and-Imagination-of-C-S-Lewis-by-Alan-Jacobs.pdf
    • http://loaminoo.linkpc.net/7098092092090099/Aventures-Fort-Boyard-6-Une-mygale-s-est-chapp-e-Fort-Boyard-F-by-Dan-Mitrecey.pdf
    • http://loaminoo.linkpc.net/7094092090099098/La-Tapisserie-de-Trajan-Et-Archambault-a-la-Decouverte-D-Une-Galerie-Internationale-de-Portraits-Du-Xve-Siecle-by-Andr-de-Mandach.pdf
    • http://loaminoo.linkpc.net/8092095098095091/The-Journals-of-Lewis-amp-Clark-1804-1806-Meriwether-Lewis-1774-1809-amp-William-Clark-1770-1838-by-Meriwether-Lewis.pdf
    • http://loaminoo.linkpc.net/4097094094098098/A-Doll-s-Story-The-fall-and-rise-of-Merr-StahlRhune-by-Lez-Lewis-by-Lez-Lewis.pdf
    • http://loaminoo.linkpc.net/2099093090099096/Novels-by-C-S-Lewis-The-Screwtape-Letters-the-Great-Divorce-Out-of-the-Silent-Planet-Till-We-Have-Faces-the-Pilgrim-s-Regress-by-C-S-Lewis.pdf
    • http://loaminoo.linkpc.net/2096099097090095/C-S-Lewis-Essay-Collection-amp-Other-Short-Pieces-by-C-S-Lewis.pdf
    • http://loaminoo.linkpc.net/9090098091094092/Prince-Caspian-the-Chronicles-of-Narnia---C-S-Lewis-by-C-S-Lewis.pdf
    • http://loaminoo.linkpc.net/1094093090095095/The-Fort-by-Bernard-Cornwell.pdf
    • http://loaminoo.linkpc.net/3094091099091099/The-Little-Red-Fort-by-Brenda-Maier.pdf
    • http://loaminoo.linkpc.net/1093096090093096/The-Fort-by-Aric-Davis.pdf
    • http://loaminoo.linkpc.net/2090098092095091/The-Fort-by-Bernard-Cornwell.pdf
    • http://loaminoo.linkpc.net/3092091099099093/Dusty-s-Fort-by-Steven-Field.pdf
    • http://loaminoo.linkpc.net/2096091097095096/Fort-Red-Border-by-Kiki-Petrosino.pdf
    • http://loaminoo.linkpc.net/7091098092093093/El-que-no-et-mata-et-fa-m-s-fort-by-David-Lagercrantz.pdf