Malicious PDF — malware analysis report

Static analysis result for SHA-256 403e1aab537aa0d0…

MALICIOUS

PDF

17.0 KB Created: 2019-05-01 19:18:57 +01:00 Authoring application: mPDF 5.7
MD5: 7b00c0ba25d8a8d545d6811ffe86fa3e SHA-1: ce0c1c6be6e7c164d2e129389caa6d1adca24f97 SHA-256: 403e1aab537aa0d09b61a52f0e9c60031b27321fc1b6c0c44d0c282e8a96f347
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a dynamic DNS domain, indicating a link farm or SEO poisoning attempt. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093092095098096/The-Nun-and-Her-Daughter-Or-Memoirs-of-the-Courville-Family-Vol-I-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/1099093099090095/Memoirs-of-a-Dutiful-Daughter-by-Simone-de-Beauvoir.pdf
    • http://loaminoo.linkpc.net/7095091094098099/Kiyoko-Memoirs-of-Sajima-s-Daughter-by-Hapa-Studios.pdf
    • http://loaminoo.linkpc.net/2092098090091097/By-Her-Own-Hand-Memoirs-of-a-Suicide-s-Daughter-by-Signe-Hammer.pdf
    • http://loaminoo.linkpc.net/3099090092099096/Yakuza-Moon-Memoirs-of-a-Gangster-s-Daughter-by-Sh-ko-Tend-.pdf
    • http://loaminoo.linkpc.net/4092093098098095/The-Hostage-s-Daughter-A-Story-of-Family-Madness-and-the-Middle-East-by-Sulome-Anderson.pdf
    • http://loaminoo.linkpc.net/1091091098091098099/The-Lapp-King-s-Daughter-A-Family-s-Journey-Through-Finland-s-Wars-by-Stina-Katchadourian.pdf
    • http://loaminoo.linkpc.net/2093093090096091/Journey-from-Obscurity-Wilfred-Owen-1893-1918-Memoirs-of-the-Owen-Family-1-Childhood-by-Harold-Owen.pdf
    • http://loaminoo.linkpc.net/1090091094092099/We-Are-Anonymous-Inside-the-Hacker-World-of-LulzSec-Anonymous-and-the-Global-Cyber-Insurgency-by-Parmy-Olson.pdf
    • http://loaminoo.linkpc.net/3093092096094092/Supervillains-Anonymous-Superheroes-Anonymous-2-by-Lexie-Dunne.pdf
    • http://loaminoo.linkpc.net/2099091094096094/Supervillains-Anonymous-Superheroes-Anonymous-2-by-Lexie-Dunne.pdf
    • http://loaminoo.linkpc.net/5093092096090094/Foodies-for-Furkids-by-D-Courville.pdf
    • http://loaminoo.linkpc.net/5093092096094091/The-Love-Panda-by-Nichols-De-Courville.pdf
    • http://loaminoo.linkpc.net/5093092096090091/Raphael-s-Story-by-Deborah-Courville.pdf
    • http://loaminoo.linkpc.net/5093092095097093/The-Courville-Rose-by-Lynn-Shurr.pdf
    • http://loaminoo.linkpc.net/5093092096094090/Edward-Said-s-Rhetoric-of-the-Secular-by-Mathieu-E-Courville.pdf
    • http://loaminoo.linkpc.net/5093092095097096/The-Exodus-Problem-and-its-Ramifications-by-Donovan-A-Courville.pdf
    • http://loaminoo.linkpc.net/5093092095097095/The-Virtual-Presenter-s-Handbook-by-Roger-Courville.pdf
    • http://loaminoo.linkpc.net/5093092095098094/The-Storm-Navigating-the-New-Economy-by-Leon-Courville.pdf
    • http://loaminoo.linkpc.net/5093092095099091/The-Inferior-Olivary-Nucleus-Anatomy-and-Physiology-by-Jacques-Courville.pdf