Malicious PDF — malware analysis report

Static analysis result for SHA-256 49cf3df255569e8b…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 04:12:19 +01:00 Authoring application: mPDF 5.7
MD5: 595fd474009454c3f5a7b4e272d80746 SHA-1: 3a98bc7f16165fcbff67dc1d7f834a947562597a SHA-256: 49cf3df255569e8b20996220adcc350d664e3b56213d849f18e460df74fb19a6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic firing suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The PDF structure and embedded links are the primary indicators of malicious activity.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092097096091093/The-Truth-About-Forever-The-Forever-Series-Book-1-by-Cole-Lepley.pdf
    • http://loaminoo.linkpc.net/3094097099095097/Planning-on-Forever-The-Forever-Series-1-by-Ashley-Wilcox.pdf
    • http://loaminoo.linkpc.net/9096096097097/Until-Dark-Until-forever-series-Book-1-by-Sheridan-Cooper.pdf
    • http://loaminoo.linkpc.net/5090091093096096/Promise-Forever-the-New-Commitment-Series-Book-1-by-Christine-Bush.pdf
    • http://loaminoo.linkpc.net/2096097096094092/The-Warlord-Wants-Forever-Immortals-After-Dark-1-by-Kresley-Cole.pdf
    • http://loaminoo.linkpc.net/4098098095092095/The-Warlord-Wants-Forever-Immortals-After-Dark-1-by-Kresley-Cole.pdf
    • http://loaminoo.linkpc.net/4096093096095/The-Warlord-Wants-Forever-Immortals-After-Dark-1-by-Kresley-Cole.pdf
    • http://loaminoo.linkpc.net/2090098099097093/The-Warlord-Wants-Forever-Immortals-After-Dark-1-by-Kresley-Cole.pdf
    • http://loaminoo.linkpc.net/1091091098090092094/The-Truth-about-Forever-by-Sarah-Dessen.pdf
    • http://loaminoo.linkpc.net/4096090091094096/The-Truth-About-Forever-by-Piper-Vaughn.pdf
    • http://loaminoo.linkpc.net/4097091098099/This-Lullaby-The-Truth-About-Forever-by-Sarah-Dessen.pdf
    • http://loaminoo.linkpc.net/3098091097092094/A-Faerie-Fated-Forever-Forever-1-by-Mary-Anne-Graham.pdf
    • http://loaminoo.linkpc.net/1091090099091094/A-Faerie-Fated-Forever-Forever-1-by-Mary-Anne-Graham.pdf
    • http://loaminoo.linkpc.net/2090091090091090/Dying-Forever-Waking-Forever-4-by-Heather-McVea.pdf
    • http://loaminoo.linkpc.net/2099094098099096/Forever-Hidden-Forever-Bluegrass-2-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/4099098094098093/Together-Forever-Caitlin-Forever-Trilogy-3-by-Francine-Pascal.pdf
    • http://loaminoo.linkpc.net/2096095096094097/Forever-Betrayed-Forever-Bluegrass-3-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/2096095096094090/Forever-Surprised-Forever-Bluegrass-6-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/1099092095093090/The-Rest-of-Forever-Firsts-and-Forever-16-by-Alexa-Land.pdf
    • http://loaminoo.linkpc.net/2091097090091094/Forever-Beth-The-Truth-Of-It-All-by-Elizabeth-Cook-Howard.pdf
    • http://loaminoo.linkpc.net/4096090091094096/The-Tr