Malicious PDF — malware analysis report

Static analysis result for SHA-256 31fd25997c21b175…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 05:11:06 +01:00 Authoring application: mPDF 5.7
MD5: 60bc340ae91ac4e8d3f5005cb704cdc2 SHA-1: e880669c3043c54a3368caadca5117f95f0bf0e3 SHA-256: 31fd25997c21b1750b5a7f29081bce76fcae8f004e13821c7d1ac11c3450e08d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that this is a technique to artificially inflate search engine rankings or distribute malicious content. While the extracted URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to redirect users to potentially harmful content or to engage in SEO manipulation for malicious purposes. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094098092093096/The-Sherlock-Holmes-Illustrated-Omnibus-The-Adventures-of-Sherlock-Holmes-the-Memoirs-of-Sherlock-Holmes-the-Hound-of-the-Baskervilles-the-Return-of-Sherlock-Holmes-A-Facsimile-of-the-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1092098092095098/Becoming-Holmes-The-Boy-Sherlock-Holmes-His-Final-Case-The-Boy-Sherlock-Holmes-6-by-Shane-Peacock.pdf
    • http://loaminoo.linkpc.net/3092099092094096/Death-on-a-Pale-Horse-Sherlock-Holmes-on-Her-Majesty-s-Secret-Service-Sherlock-Holmes-6-by-Donald-Serrell-Thomas.pdf
    • http://loaminoo.linkpc.net/1090097096093094093/Young-Sherlock-Holmes-Das-Leben-ist-t-dlich---Sherlock-Holmes-ermittelt-in-Amerika-by-Andy-Lane.pdf
    • http://loaminoo.linkpc.net/8098099093093095/Die-Abenteuer-des-Sherlock-Holmes-Sherlock-Holmes-Ausgabe-Band-1-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/1091090097091091099/Young-Sherlock-Holmes-Nur-der-Tod-ist-umsonst---Sherlock-Holmes-ermittelt-in-Schottland-by-Andy-Lane.pdf
    • http://loaminoo.linkpc.net/1090093098095092/The-Original-Illustrated-Sherlock-Holmes-Sherlock-Holmes-3-6-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/2091095090099093/The-Case-Book-of-Sherlock-Holmes-Sherlock-Holmes-9-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/3095098093096/The-Return-of-Sherlock-Holmes-Sherlock-Holmes-6-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/3092090090091091/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/6091099091097092/The-Adventures-of-Sherlock-Holmes-Sherlock-Holmes-3-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/3094092091093/The-Memoirs-of-Sherlock-Holmes-Sherlock-Holmes-4-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/4095093095097094/Sherlock-Holmes-Sherlock-Holmes-1-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/8091091092090096/The-Daughter-of-Sherlock-Holmes-The-Daughter-of-Sherlock-Holmes-Mysteries-1-by-Leonard-Goldberg.pdf
    • http://loaminoo.linkpc.net/2095097092094093/Sherlock-The-Memoirs-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/4091091095092092/Sherlock-Holmes-time-detective-by-Adrian-Sherlock.pdf
    • http://loaminoo.linkpc.net/4098095093/Mrs-Sherlock-Holmes-by-Brad-Ricca.pdf
    • http://loaminoo.linkpc.net/7094094090096093/Sherlock-Holmes-en-Sib-rie-by-P-Orlovets.pdf
    • http://loaminoo.linkpc.net/2090097097095093/The-Progress-of-Sherlock-Holmes-by-Ivy-Blossom.pdf
    • http://loaminoo.linkpc.net/2095096095097093/Sherlock-Holmes-The-Man-and-His-World-by-H-R-F-Keating.pdf
    • http://loaminoo.linkpc.net/1090097096093094093/Young-Sherlock-Holmes-Das-Leben-ist-t-dlich---Sherlock-H