Malicious PDF — malware analysis report

Static analysis result for SHA-256 451e4147f2d35e19…

MALICIOUS

PDF

19.7 KB Created: 2019-04-30 04:18:37 +01:00 Authoring application: mPDF 5.7
MD5: 62ec3f91f7c553c4156d01619dfd49bf SHA-1: d0c96b72e29afb6c2ffaa172892a0353e505a88f SHA-256: 451e4147f2d35e199d19dd49460346b0a1a48f52d901bcdf86a5fc4ce97eefdc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a significant number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential for hosting malicious content or redirecting users to phishing sites. The document body itself is heavily obfuscated and does not provide clear textual clues about its intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090093093098096/Chronicle-of-the-Roman-Emperors-The-Reign-by-Reign-Record-of-the-Rulers-of-Imperial-Rome-by-Christopher-Scarre.pdf
    • http://loaminoo.linkpc.net/4092091096097098/Keeper-of-Reign-Reign-1-by-Emma-Right.pdf
    • http://loaminoo.linkpc.net/1091098092095097092/Journal-of-the-Plague-Year-An-Insider-s-Chronicle-of-Eliot-Spitzer-s-Short-and-Tragic-Reign-by-Lloyd-Constantine.pdf
    • http://loaminoo.linkpc.net/6091099096095092/Julius-Caesar-Passing-the-Point-of-No-Return-Roman-General-and-Statesman-Julius-Caesar-Turned-the-Roman-Republic-Into-the-Powerful-Roman-Empire-a-Coup-Ended-His-Reign-and-His-Life-on-the-Ides-of-March-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/7092091091/Reign-of-the-Fallen-Reign-of-the-Fallen-1-by-Sarah-Glenn-Marsh.pdf
    • http://loaminoo.linkpc.net/1091098097098092093/Legions-of-Rome-The-Definitive-History-of-Every-Imperial-Roman-Legion-by-Stephen-Dando-Collins.pdf
    • http://loaminoo.linkpc.net/1091097096092090094/A-History-of-Rome-Under-the-Emperors-by-Thomas-Wiedemann.pdf
    • http://loaminoo.linkpc.net/7090095092097095/Reign-Over-Me-by-Rebecca-Brochu.pdf
    • http://loaminoo.linkpc.net/1093091097094/Rain-Reign-by-Ann-M-Martin.pdf
    • http://loaminoo.linkpc.net/4095097094096096/Reign-of-Ice-Forever-Fae-4-by-L-P-Dover.pdf
    • http://loaminoo.linkpc.net/1097092096093094/The-Stormcaller-Twilight-Reign-1-by-Tom-Lloyd.pdf
    • http://loaminoo.linkpc.net/2090098098/Reign-The-Henchmen-MC-1-by-Jessica-Gadziala.pdf
    • http://loaminoo.linkpc.net/4094097093095096/Reign-of-Silence-by-Tony-Martin.pdf
    • http://loaminoo.linkpc.net/3095099096095097/JSA-Vol-8-Black-Reign-by-Geoff-Johns.pdf
    • http://loaminoo.linkpc.net/3095096096091097/A-Heart-of-Reign-by-Ornitha-Danielle.pdf
    • http://loaminoo.linkpc.net/3090097097097098/Cthulhu-s-Reign-by-Darrell-Schweitzer.pdf
    • http://loaminoo.linkpc.net/7091099091/Reign-the-Earth-The-Elementae-1-by-A-C-Gaughen.pdf
    • http://loaminoo.linkpc.net/2091094090091099/Akito-Alpha-s-Reign-2-by-Zoe-Perdita.pdf
    • http://loaminoo.linkpc.net/3095093094090095/The-Ragged-Man-Twilight-Reign-4-by-Tom-Lloyd.pdf
    • http://loaminoo.linkpc.net/5093094092094/Free-Reign-by-Rosemary-Aubert.pdf
    • http://loaminoo.linkpc.net/6091099096095092/Julius-Caesar-Passing-the-Point-of-No-Return-Roman-General-and-Statesman-Julius-Caesar-Turned-the-Roman-Republic-Into-the-Powerful-Roman-Empire-a-Coup-Ended-His-Reign-and-His-Life-on-the-Ides-of-March-by-William-Shakespeare