Malicious PDF — malware analysis report

Static analysis result for SHA-256 58531980af19153c…

MALICIOUS

PDF

19.0 KB Created: 2019-05-07 03:43:57 +01:00 Authoring application: mPDF 5.7
MD5: 4cc70045cb75a8e8d36068f4bd69031b SHA-1: 53308b94b8a8beb1d3f9ea2bfedd78b8c45ff6cd SHA-256: 58531980af19153c55bb0b20b82e61d70690d4801e3eea3aa106e262cfcb83e6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a potential SEO poisoning or link farm attack. The embedded URLs are the primary indicators of malicious activity in this sample. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098094099091091/Winter-in-the-Morning-A-Young-Girl-s-Life-in-the-Warsaw-Ghetto-and-Beyond-1939-1945-by-Janina-Bauman.pdf
    • http://loaminoo.linkpc.net/1098095094090091/The-Pianist-The-Extraordinary-True-Story-of-One-Man-s-Survival-in-Warsaw-1939-1945-by-W-adys-aw-Szpilman.pdf
    • http://loaminoo.linkpc.net/4098097090095095/Vanished-City-Everyday-Life-in-the-Warsaw-Ghetto-by-Michel-Mazor.pdf
    • http://loaminoo.linkpc.net/4095092092093093/Notes-from-the-Warsaw-Ghetto-by-Emmanuel-Ringelblum.pdf
    • http://loaminoo.linkpc.net/3098094092092099/Britain-at-War-1939-to-1945-What-Was-Life-Like-During-the-War-by-James-Lingard.pdf
    • http://loaminoo.linkpc.net/2097097097095095/The-Warsaw-Ghetto-A-Guide-to-the-Perished-City-by-Barbara-Engelking.pdf
    • http://loaminoo.linkpc.net/3098094092094092/Ivan-s-War-Life-and-Death-in-the-Red-Army-1939-1945-by-Catherine-Merridale.pdf
    • http://loaminoo.linkpc.net/1090090093099090094/Irena-Sendler-and-the-Children-of-the-Warsaw-Ghetto-by-Susan-Goldman-Rubin.pdf
    • http://loaminoo.linkpc.net/5090097093093099/Who-Will-Write-Our-History-Rediscovering-a-Hidden-Archive-from-the-Warsaw-Ghetto-by-Samuel-D-Kassow.pdf
    • http://loaminoo.linkpc.net/1090095090096099090/Der-Beginn-des-Krieges-EVENT-in-1939-1941-by-Janina-Muench.pdf
    • http://loaminoo.linkpc.net/4097097096092093/Mother-and-Me-Escape-from-Warsaw-1939-by-Julian-Padowicz.pdf
    • http://loaminoo.linkpc.net/3098094099091096/A-Surplus-of-Memory-Chronicle-of-the-Warsaw-Ghetto-Uprising-by-Yitzhak-quot-Antek-quot-Zuckerman.pdf
    • http://loaminoo.linkpc.net/6092099091094091/MI9-Escape-and-Evasion-1939-1945-by-M-R-D-Foot.pdf
    • http://loaminoo.linkpc.net/7091097099091/No-Less-Than-Victory-World-War-II-1939-1945-3-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/9093090094097094/Letters-to-Freya-1939-1945-by-Helmuth-James-von-Moltke.pdf
    • http://loaminoo.linkpc.net/7090097092093/The-Steel-Wave-World-War-II-1939-1945-2-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/1091093093095098093/The-Secret-War-Spies-Codes-and-Guerrillas-1939-1945-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/7092097094096/The-Final-Storm-World-War-II-1939-1945-4-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/9091092094096095/Struggle-Death-Memory-1939-1945-by-Stanislaw-Poznanski.pdf
    • http://loaminoo.linkpc.net/9094092093099096/Warsaw-1944-Hitler-Himmler-and-the-Warsaw-Uprising-by-Alexandra-Richie.pdf
    • http://loaminoo.linkpc.net/1090090093099090094/Irena-Sendler-and-the-C