Malicious PDF — malware analysis report

Static analysis result for SHA-256 48d8beb9bbad2c98…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 05:22:04 +01:00 Authoring application: mPDF 5.7
MD5: 760c278b22a395a164f4f365df045ab2 SHA-1: 964c9191624b5938ec047c01571722dfe30c056f SHA-256: 48d8beb9bbad2c9860361a5c4feb1a09fc51c2b6d3d179a97e39aea31534d052
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a potential SEO manipulation or content distribution scheme. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic indicate a malicious intent to leverage the PDF for link farming or to redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5097095098095099/Grey---Fifty-Shades-of-Grey-von-Christian-selbst-erz-hlt-Fifty-Shades-4-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/1090091094098094097/Fifty-Shades-of-Grey-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/1090092091/Grey-Fifty-Shades-4-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/7099093094095/Fifty-Shades-Duo-Fifty-Shades-Darker-Fifty-Shades-Freed-Fifty-Shades-2-3-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/6091091093093093/Fifty-Shades-of-Grey-Part-2-of-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/1097091091092090/Meet-Fifty-Shades-Continued---Fifty-Shades-of-Grey-by-G-E-Griffin.pdf
    • http://loaminoo.linkpc.net/1090095095092095096/Satutettu-Fifty-Shades-of-Grey-Christianin-kertomana-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/7091096093095098/Fifty-Shades-of-Grey-Peninta-apohrosis-tou-Gkri-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/5097095098096097/Darker---Fifty-Shades-of-Grey-Gef-hrliche-Liebe-von-Christian-selbst-erz-hlt-Band-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/1090091090090099/Grey-Fifty-Shades-of-Grey-as-Told-by-Christian-A-11-Minute-HOOOTTTT-summary-by-Bern-Bolo.pdf
    • http://loaminoo.linkpc.net/3093092099096093/Fifty-Shades-Freed-Fifty-Shades-3-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/2094090094099094/Fifty-Shades-Darker-Fifty-Shades-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/3090096092096090/The-Fifty-Shades-of-Grey-Phenomena-by-Chloe-Thurlow.pdf
    • http://loaminoo.linkpc.net/6098098096092091/Married-Sex-Fifty-Shades-of-Grey-for-Couples-by-Laina-Charleston.pdf
    • http://loaminoo.linkpc.net/3093099092094093/Fifty-Shades-of-Lady-Catherine-Grey-The-Sex-Scandals-that-Shook-the-Tudor-Court-by-T-S-Wiseman.pdf
    • http://loaminoo.linkpc.net/6097097092/Darker-Fifty-Shades-as-Told-by-Christian-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/5097090090099094/Befreite-Lust-Shades-of-Grey-3-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/8093091091095098/Gef-hrliche-Liebe-Shades-of-Grey-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/1097096091091095/Shades-of-Grey-Shades-of-Grey-1-by-Jasper-Fforde.pdf
    • http://loaminoo.linkpc.net/1091092090094094/Shades-of-Grey-Shades-of-Grey-1-by-Jasper-Fforde.pdf
    • http://loaminoo.linkpc.net/5097095098096097/Darker---Fifty-Shades-of-Grey-Gef-hrliche-Liebe-von-Ch