Malicious PDF — malware analysis report

Static analysis result for SHA-256 31e030517e233659…

MALICIOUS

PDF

22.0 KB Created: 2019-04-30 03:16:00 +01:00 Authoring application: mPDF 5.7
MD5: 5f50ccf725112238a71e1e32a261730b SHA-1: 3678dc488e0361dc2bd9b2c3af5730049a2fea0b SHA-256: 31e030517e23365965ccae0be9e4e841bdbce77e429326ac4625468984aea68f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to external content. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to drive traffic or potentially distribute further content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097092092097094/Tea-Time-for-the-Traditionally-Built-No-1-Ladies-Detective-Agency-10-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1090098098092/Tea-Time-for-the-Traditionally-Built-No-1-Ladies-Detective-Agency-10-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1092094099096094/The-No-1-Ladies-Detective-Agency-Set-The-No-1-Ladies-Detective-Agency-Tears-of-the-Giraffe-Morality-for-Beautiful-Girls-The-Kalahari-Typing-School-For-Men-The-Full-Cupboard-of-Life-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4090098093097099/Precious-and-Grace-No-1-Ladies-Detective-Agency-17-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1094090094090093/Tears-of-the-Giraffe-No-1-Ladies-Detective-Agency-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/6098092098/The-House-of-Unexpected-Sisters-No-1-Ladies-Detective-Agency-18-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7098096095096/Morality-for-Beautiful-Girls-No-1-Ladies-Detective-Agency-3-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4098099097094097/The-Kalahari-Typing-School-for-Men-No-1-Ladies-Detective-Agency-4-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3095094096093090/The-Miracle-at-Speedy-Motors-No-1-Ladies-Detective-Agency-9-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1090095090094/The-Double-Comfort-Safari-Club-No-1-Ladies-Detective-Agency-11-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1098096093092099/The-Saturday-Big-Tent-Wedding-Party-No-1-Ladies-Detective-Agency-12-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1091096090096093091/A-Work-of-Beauty-Alexander-McCall-Smith-s-Edinburgh-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093091095094092/One-City-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7099097091091092/Amori-in-viaggio-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093094097096098/Tears-of-the-Giraffe-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7093098093098096/The-Joke-Machine-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/6098090098097090/Akimbo-and-the-Elephants-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/9096094092099099/T-r-an-T-r-in-der-44-Scotland-Street-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7090094090092092/Les-larmes-de-la-girafe-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/2091097094099090/The-Dog-who-Came-in-from-the-Cold-Corduroy-Mansions-2-by-Alexander-McCall-Smith.pdf