Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e10f050fb23d499…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 01:07:55 +01:00 Authoring application: mPDF 5.7
MD5: 8714e74f4b779ee1e61ce018414913a8 SHA-1: 3c38562ba5158c07435be4f5afa4dbb569ec7f57 SHA-256: 4e10f050fb23d49973c29d3446a17ce34bb46785ff14433132593f39f247ea02
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. While no scripts were extracted, the sheer volume of links and the suspicious domain indicate a likely attempt to drive traffic to potentially harmful resources.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092092092096091/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://loaminoo.linkpc.net/1096097097091097/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://loaminoo.linkpc.net/3094097096090090/One-Fish-Two-Fish-Red-Fish-Blue-Fish-by-Dr-Seuss.pdf
    • http://loaminoo.linkpc.net/4097092096093092/Red-Fish-Dead-Fish-Fish-Out-of-Water-2-by-Amy-Lane.pdf
    • http://loaminoo.linkpc.net/8090096094097097/My-Rainbow-Fish-Book-Box-by-Marcus-Pfister.pdf
    • http://loaminoo.linkpc.net/9097098099096095/When-Do-Fish-Sleep-An-Imponderables-Book-by-David-Feldman.pdf
    • http://loaminoo.linkpc.net/1096098094096091/Fish-Out-of-Water-Fish-Out-of-Water-1-by-Amy-Lane.pdf
    • http://loaminoo.linkpc.net/5090095091098091/Sink-or-Swim-Exploring-Schools-of-Fish-A-Branches-Book-The-Magic-School-Bus-Rides-Again-1-by-Judy-Katschke.pdf
    • http://loaminoo.linkpc.net/6092092098096091/Fish-Also-Go-To-Heaven-Children-s-Book-value-tales-bedtime-story-kid-s-short-story-collection-by-Ms-Tammy-Brown-Elkeles.pdf
    • http://loaminoo.linkpc.net/6092092097098094/Children-s-Book-Fish-Also-Go-To-Heaven-value-tales-bedtime-story-kid-s-short-story-collection-by-Tammy-Brown-Elkeles.pdf
    • http://loaminoo.linkpc.net/3091093093093095/Baby-Goofy-Catches-A-Fish-A-Book-About-Rhyming-Words-Baby-s-First-Disney-Books-by-Walt-Disney-Company.pdf
    • http://loaminoo.linkpc.net/2096094090095090/Saving-Fish-from-Drowning-by-Amy-Tan.pdf
    • http://loaminoo.linkpc.net/5092092095090098/The-Fish-are-Laughing-by-Will-Nixon.pdf
    • http://loaminoo.linkpc.net/7098096097095091/The-Fish-and-the-Cat-by-Marianne-Dubuc.pdf
    • http://loaminoo.linkpc.net/6097093097099091/How-Many-Fish-by-Caron-Lee-Cohen.pdf
    • http://loaminoo.linkpc.net/3096091093099090/Like-a-Fish-by-Daniel-Crocker.pdf
    • http://loaminoo.linkpc.net/7090096094097/Fish-for-Supper-by-M-B-Goffstein.pdf
    • http://loaminoo.linkpc.net/5090094092094093/Rumble-Fish-by-S-E-Hinton.pdf
    • http://loaminoo.linkpc.net/3094096094095/Saving-Fish-from-Drowning-by-Amy-Tan.pdf
    • http://loaminoo.linkpc.net/3097094091095090/Fish-You-Were-Here-by-Colleen-A-F-Venable.pdf
    • http://loaminoo.linkpc.net/5090095091098091/Sink-or-Swim-Exploring-Schools-of-Fish