Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b3bd1789e156267…

MALICIOUS

PDF

23.5 KB Created: 2019-05-07 06:13:53 +01:00 Authoring application: mPDF 5.7
MD5: 62df1d1fd35058b23ecff60dfbedaa65 SHA-1: 10e7a73cc39913d2b7bcd4db0b35ae95e98686a4 SHA-256: 2b3bd1789e1562670284513c75be455148d024b00b7ccad9369e78e535f5c9c6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The embedded URLs are designed to appear as legitimate book titles, likely as a lure. No scripts were extracted from this sample, and the document body was heavily obfuscated, limiting further analysis of the exact user-facing content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091098094094098097/The-world-of-Shakespeare-Hamlet-and-Julius-Caesar-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/4094099091099099/The-Landmark-Julius-Caesar-The-Complete-Works-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/6091099096095092/Julius-Caesar-Passing-the-Point-of-No-Return-Roman-General-and-Statesman-Julius-Caesar-Turned-the-Roman-Republic-Into-the-Powerful-Roman-Empire-a-Coup-Ended-His-Reign-and-His-Life-on-the-Ides-of-March-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1090098099094098091/Complete-Works-of-William-Shakespeare-154-Sonnets-Romeo-and-Juliet-Othello-Hamlet-Macbeth-Antony-and-Cleopatra-The-Tempest-Julius-Caesar-King-Cressida-The-Winter-s-Tale-amp-more-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/5096097098099092/The-Gallic-Wars---La-Guerre-des-Gaules---French-English-Bilingual-Edition-French-English-Bilingual-Edition-Illustrated-of-Julius-Caesar-De-Bello-Gallico-Point-Media-Publishing---History-Book-1-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/1099091092099094/Caesar-s-Commentaries-On-the-Gallic-War-amp-On-the-Civil-War-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/1091098094094093091/Key-of-Junichirou-Tanizaki-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094093091097/The-Human-chair-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094094093097/Play-of-the-child-3-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/6094092098098092/Caesar-s-Gallic-War-1898-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/1091098094094092098/Romeo-and-Juliet-of-Shakespeare-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094093092097/Book-of-Five-Rings-by-Musashi-MIYAMOTO-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094094093092/Desire-for-exchange-Full-version-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094094093090/Book-of-Five-Rings-by-Musashi-Miyamoto-full-version-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094094098096/Kusamakura-and-Kokoro-by-Soseki-NATSUME-Full-version-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1091098094094092093/haiku-of-Shiki-MASAOKA-and-Picture-of-Fuji-of-Hokusai-KATSUSHIKA-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/1090099093092091098/The-world-of-Ranpo-Edogawa-The-Human-chair-and-Blindness-Beast-by-shogo-kisaragi.pdf
    • http://loaminoo.linkpc.net/3093092092090093/Caesar-s-Commentaries-the-Complete-Gallic-Wars-Revised-Revised-Edition-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/1091094091091095093/The-Civil-War-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/4094098090098098/The-Civil-War-by-Gaius-Julius-Caesar.pdf