Malicious PDF — malware analysis report

Static analysis result for SHA-256 447a8df91af3d170…

MALICIOUS

PDF

14.1 KB Created: 2019-04-30 05:49:34 +01:00 Authoring application: mPDF 5.7
MD5: 785fddbec4a9d3c473e03f1aaab2a61e SHA-1: 8a4b396617b087f5bf923493a49fd375ec3c9348 SHA-256: 447a8df91af3d17040bd9f3f47f84d50d4c2075fc5ddfaef01bbb34d21a3332d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a multitude of external sites. No scripts were extracted from this sample. The URLs themselves appear to be benign, but the sheer volume and the nature of the heuristic firing suggest a malicious intent to redirect users.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1098096090092090/The-Last-Hope-Warriors-Omen-of-the-Stars-6-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/7098095091090096/The-Fourth-Apprentice-Warriors-Omen-of-the-Stars-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/1093096092094096/Path-of-Stars-Warriors-Dawn-of-the-Clans-6-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/5098099095090/Warriors-Battles-of-the-Clans-Warriors-Field-Guide-4-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/4092097090091/Twilight-amp-Into-the-Wild-Warriors-The-New-Prophecy-5-and-Warriors-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3098095096099/Warriors-Boxed-Set-Warriors-1-3-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/4096091090092093/Into-the-Wild-Warriors-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/1091092092097099/Warriors-Specials-Box-Set-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/2098096092092095/Into-the-Wild-Warriors-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3098095092093/The-Sight-Warriors-Power-of-Three-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/2093091090096093/Outcast-Warriors-Power-of-Three-3-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/8096098090097/Warriors-The-Untold-Stories-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3094090094099/The-Darkest-Hour-Warriors-6-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3094090095092/Forest-of-Secrets-Warriors-3-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3094092097096/Rising-Storm-Warriors-4-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3095090096098/Dawn-Warriors-The-New-Prophecy-3-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3094093091095094/Sunset-Warriors-The-New-Prophecy-6-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/4095098092092091/Midnight-Warriors-The-New-Prophecy-1-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/4091090096091/Warriors-Tigerstar-and-Sasha-1-Into-the-Woods-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3098096096096/Long-Shadows-Warriors-Power-of-Three-5-by-Erin-Hunter.pdf
    • http://loaminoo.linkpc.net/3094090094099/The-Darkest-Hour-Warriors-6-by-Erin-H