Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d831f2eabf9e229…

MALICIOUS

PDF

12.7 KB Created: 2019-05-01 20:37:17 +01:00 Authoring application: mPDF 5.7
MD5: db98c6b567f07958a4fc0e9b5a8d9bbf SHA-1: 2accc786f6bc50dc909804f862a2522c55a24d78 SHA-256: 2d831f2eabf9e22994122c61cd6bb7d3e6912ed67f0e8a7745053f25d784460d
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented as book titles, suggesting a social engineering tactic to encourage clicks. The SE_URGENCY_LURE heuristic also fired, indicating the document may contain language designed to create a false sense of urgency. No scripts were extracted from this sample. The primary attack vector appears to be directing users to a large number of external PDF files hosted on a single domain.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096093092094098/Threats-at-Three-by-Ann-Purser.pdf
    • http://loaminoo.linkpc.net/2094096093095094/Murder-On-Monday-by-Ann-Purser.pdf
    • http://loaminoo.linkpc.net/3091092094092098/The-Pendragon-Protocol-by-Philip-Purser-Hallard.pdf
    • http://loaminoo.linkpc.net/8099091091093/Without-Warning-Shaken-1-by-K-G-MacGregor.pdf
    • http://loaminoo.linkpc.net/2096096093097091/The-Warning-Animorphs-16-by-K-A-Applegate.pdf
    • http://loaminoo.linkpc.net/4092092098091093/Red-Sky-Warning-by-Wendy-L-Young.pdf
    • http://loaminoo.linkpc.net/6097093091094094/Without-Warning-Vigilance-2-by-Desiree-Holt.pdf
    • http://loaminoo.linkpc.net/3099092096091097/Storm-Warning-by-Jack-Higgins.pdf
    • http://loaminoo.linkpc.net/2090095098099/Final-Warning-by-Sandra-Robbins.pdf
    • http://loaminoo.linkpc.net/1090096096092096098/Unheeded-Warning-by-Man-s-Sperber.pdf
    • http://loaminoo.linkpc.net/1095094093091093/Fascism-A-Warning-by-Madeleine-K-Albright.pdf
    • http://loaminoo.linkpc.net/4093093091091092/Warning-Light-by-David-Ricciardi.pdf
    • http://loaminoo.linkpc.net/3098098099094090/The-Ambler-Warning-by-Robert-Ludlum.pdf
    • http://loaminoo.linkpc.net/4092099095095095/Without-Warning-The-Disappearance-1-by-John-Birmingham.pdf
    • http://loaminoo.linkpc.net/4090099098091092/Sailors-Take-Warning-by-Malcolm-Torres.pdf
    • http://loaminoo.linkpc.net/8097094099095096/Trigger-Warning-by-John-Raptor.pdf
    • http://loaminoo.linkpc.net/1091097092098092/A-Warning-Thunder-by-John-Leckel.pdf
    • http://loaminoo.linkpc.net/6091094095096/The-Warning-Voice-The-Story-of-the-Stone-3-by-Cao-Xueqin.pdf
    • http://loaminoo.linkpc.net/3098096092096097/Stark-Warning-by-James-Jaime-Raven.pdf
    • http://loaminoo.linkpc.net/3095096097098/Storm-Warning-The-39-Clues-9-by-Linda-Sue-Park.pdf