Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c02861a29e59e51…

MALICIOUS

PDF

13.9 KB Created: 2019-05-07 03:44:17 +01:00 Authoring application: mPDF 5.7
MD5: 5ea8da2b2bf8dcb27e82a7d6e898d43b SHA-1: 0b8e82dea12e78a03abddc1b87688c98bc9d9390 SHA-256: 3c02861a29e59e510ebf4c08a809b83bb9c45bdf30dc57af74792ca6288f6cbe
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious PDF

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5098096099097091/Caf-des-Artistes-by-John-Hartley-Williams.pdf
    • http://loaminoo.linkpc.net/5098097090090092/Les-Artistes-by-ch-Braquehaye.pdf
    • http://loaminoo.linkpc.net/5098096099090090/The-Variety-Artistes-by-Tom-Wakefield.pdf
    • http://loaminoo.linkpc.net/5098096098099097/Artistes-Sans-Oeuvres-I-Would-Prefer-Not-To-by-Jean-Yves-Jouannais.pdf
    • http://loaminoo.linkpc.net/4091097097098097/The-Man-Who-Cried-I-Am-A-Novel-by-John-A-Williams.pdf
    • http://loaminoo.linkpc.net/8090096097090/WALKAWAY730-by-John-Williams-III.pdf
    • http://loaminoo.linkpc.net/3090099096094/Augustus-by-John-Williams.pdf
    • http://loaminoo.linkpc.net/8093090098095/Stoner-by-John-Williams.pdf
    • http://loaminoo.linkpc.net/1091092094093098095/Nothing-But-the-Night-by-John-Williams.pdf
    • http://loaminoo.linkpc.net/4098096097095098/Clifford-s-Blues-A-Novel-by-John-A-Williams.pdf
    • http://loaminoo.linkpc.net/1090095099097094090/Sam-Houston-by-John-Hoyt-Williams.pdf
    • http://loaminoo.linkpc.net/5098098093094090/Captain-Blackman-by-John-A-Williams.pdf
    • http://loaminoo.linkpc.net/9094097092098094/Bruxelles-Colonie-D-Artistes-Peintres-Hollandais-1850-1890-by-Saskia-De-Bodt.pdf
    • http://loaminoo.linkpc.net/5097097094095090/Hub-Fans-Bid-Kid-Adieu-John-Updike-on-Ted-Williams-by-John-Updike.pdf
    • http://loaminoo.linkpc.net/1091092092095091094/Sayuri-s-Theme-And-End-Credits-by-John-Williams.pdf
    • http://loaminoo.linkpc.net/6092092092099091/What-Is-Existence-by-Christopher-John-Fards-Williams.pdf
    • http://loaminoo.linkpc.net/1094098090094/Tennessee-Williams-Mad-Pilgrimage-of-the-Flesh-by-John-Lahr.pdf
    • http://loaminoo.linkpc.net/6092096095098/Red-Men-Liverpool-Football-Club-The-Biography-by-John-Williams.pdf
    • http://loaminoo.linkpc.net/2093096092095/George-Washington-Williams-A-Biography-by-John-Hope-Franklin.pdf
    • http://loaminoo.linkpc.net/3090094095097/Roger-Williams-and-the-Creation-of-the-American-Soul-by-John-M-Barry.pdf
    • http://loaminoo.linkpc.net/5097097094095090/Hub-Fans-Bid-Kid-Adieu-John-Updike-o