Malicious PDF — malware analysis report

Static analysis result for SHA-256 796dee4bc2273c1f…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 05:19:08 +01:00 Authoring application: mPDF 5.7
MD5: 44c91d759680134257cb9990b2060f06 SHA-1: 5810e0f8d0a97bc39974347a6edd942072925343 SHA-256: 796dee4bc2273c1fa5d4b62832f7fee1b50834a89c56022a37dfe8e04da268fd
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO manipulation or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to drive traffic or potentially serve other payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099090091091098/The-Clare-Kane-Identity-Clare-Kane-2-by-L-M-Severin.pdf
    • http://loaminoo.linkpc.net/1090095098095091/The-Clare-Kane-Project-Clare-Kane-1-by-L-M-Severin.pdf
    • http://loaminoo.linkpc.net/6091099091091097/Back-to-St-Clare-s-Second-Form-at-St-Clare-s---Claudine-at-St-Clare-s---Fifth-Formers-of-St-Clare-s-by-Enid-Blyton.pdf
    • http://loaminoo.linkpc.net/6091099091092097/St-Clare-s-Claudine-At-St-Clare-s-amp-Fifth-Formers-At-St-Clare-s-by-Enid-Blyton.pdf
    • http://loaminoo.linkpc.net/1090096092097093099/Report-of-the-Executive-Committee-in-Charge-of-Kane-Lodge-Reception-to-Bro-Robert-Edwin-Peary-U-S-N-and-Other-Arctic-Explorers-at-Sherry-s-New-York-April-8th-1896-by-Freemasons-Kane-Lodge-No-454.pdf
    • http://loaminoo.linkpc.net/2093096098091099/Summer-Term-at-St-Clare-s-St-Clare-s-3-by-Enid-Blyton.pdf
    • http://loaminoo.linkpc.net/2098096096099099/The-Sixth-Form-at-St-Clare-s-St-Clare-s-8-by-Pamela-Cox.pdf
    • http://loaminoo.linkpc.net/4092090094096094/The-Third-Form-at-St-Clare-s-St-Clare-s-7-by-Pamela-Cox.pdf
    • http://loaminoo.linkpc.net/1090090093096095090/I-Let-You-Go-Paperback-7-Jun-2015-by-Clare-Mackintosh-by-Clare-Mackintosh.pdf
    • http://loaminoo.linkpc.net/3093098091092091/Blackmark-by-Gil-Kane.pdf
    • http://loaminoo.linkpc.net/1091093090092092/Cry-Blue-Murder-by-Kim-Kane.pdf
    • http://loaminoo.linkpc.net/4097098093099092/Islands-by-Samantha-Kane.pdf
    • http://loaminoo.linkpc.net/2093090092093093/Samantha-by-Andrea-Kane.pdf
    • http://loaminoo.linkpc.net/8091096096097093/Tu-elegida-by-Ishanna-Kane.pdf
    • http://loaminoo.linkpc.net/3093090099091098/Sweet-Submissions-IV-by-Sean-O-39-Kane.pdf
    • http://loaminoo.linkpc.net/3097096094095094/The-Hand-of-Kane-by-Robert-E-Howard.pdf
    • http://loaminoo.linkpc.net/3099096099094095/A-Titan-for-Christmas-by-Aria-Kane.pdf
    • http://loaminoo.linkpc.net/1096098096093097/Tara-Kane-by-George-Markstein.pdf
    • http://loaminoo.linkpc.net/3095097091094097/Gift-of-Desire-by-Samantha-Kane.pdf
    • http://loaminoo.linkpc.net/4096093096098/The-Kane-Chronicles-1-3-by-Rick-Riordan.pdf
    • http://loaminoo.linkpc.net/1090096092097093099/Report-of-the-Executive-Committee-in-Charge-of-Kane-Lodge-