Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a6e34a2309cc35f…

MALICIOUS

PDF

18.6 KB Created: 2019-05-07 09:44:42 +01:00 Authoring application: mPDF 5.7
MD5: 768f641d4d4d5708a1837c0522cb6add SHA-1: 68d6052411adbc38259bace5a1dedcb869408b59 SHA-256: 7a6e34a2309cc35f0ce2a80f0c8d0894dfc14aaa98d46547f7a42ce09bbf4804
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a technique to generate SEO traffic or potentially distribute malicious content. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users to external sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092092094095095/Dark-Horse-Dark-Horse-1-by-Kate-Sherwood.pdf
    • http://loaminoo.linkpc.net/3092092097094096/Rough-Broke-Dark-Horse-1-2-by-Kate-Sherwood.pdf
    • http://loaminoo.linkpc.net/2098095092097094/The-Dark-Horse-Book-of-Monsters-The-Dark-Horse-Book-of-4-by-Scott-Allie.pdf
    • http://loaminoo.linkpc.net/8099097096095/Dark-Horse-Presents-35-by-Mike-Richardson.pdf
    • http://loaminoo.linkpc.net/3094098090095097/Dark-Horse-Class-5-1-by-Michelle-Diener.pdf
    • http://loaminoo.linkpc.net/1091093096098097096/The-Dark-Horse-of-Shanghai-by-Kent-Sorensen.pdf
    • http://loaminoo.linkpc.net/7098094094097092/DARK-HORSE-ASSASSIN-Rise-of-the-Messiah-by-Jihad.pdf
    • http://loaminoo.linkpc.net/1093094092091092/Bound-Dark-Horse-Series-Book-1-by-J-S-Scott.pdf
    • http://loaminoo.linkpc.net/2093093094095091/Lightning-s-Daughter-Dark-Horse-2-by-Mary-H-Herbert.pdf
    • http://loaminoo.linkpc.net/7097096095094097/Dark-Horse-Whitehorse-Montana-The-McGraw-Kidnapping-1-by-B-J-Daniels.pdf
    • http://loaminoo.linkpc.net/2096090090097093/Woman-King-Dark-Horse-Trilogy-1-by-Evette-Davis.pdf
    • http://loaminoo.linkpc.net/4094090099096093/Dark-Horse-The-Life-And-Art-Of-George-Harrison-by-Geoffrey-Giuliano.pdf
    • http://loaminoo.linkpc.net/1090097099099090095/Death-by-a-Dark-Horse-Thea-Campbell-Mysteries-1-by-Susan-Schreyer.pdf
    • http://loaminoo.linkpc.net/4093096093090091/Wonder-Horse-The-True-Story-of-the-World-s-Smartest-Horse-by-Emily-Arnold-McCully.pdf
    • http://loaminoo.linkpc.net/1091091098096090/The-Horse-Charmer-Phantom-Stallion-Wild-Horse-Island-1-by-Terri-Farley.pdf
    • http://loaminoo.linkpc.net/4096096090098099/Cross-Train-Your-Horse-Book-One-Simple-Dressage-for-Every-Horse-Every-Sport-by-Jane-Savoie.pdf
    • http://loaminoo.linkpc.net/4099094097098092/Sun-Horse-Moon-Horse-by-Rosemary-Sutcliff.pdf
    • http://loaminoo.linkpc.net/2092097092090090/War-Horse-War-Horse-1-by-Michael-Morpurgo.pdf
    • http://loaminoo.linkpc.net/1096092098099090/Western-genre-Novels-including-The-Dark-Tower-Ii-The-Drawing-Of-The-Three-The-Dark-Tower-The-Gunslinger-The-Dark-Tower-Iv-Wizard-And-Glass-The-Dark-Tower-Iii-The-Waste-Lands-The-Dark-Tower-V-Wolves-Of-The-Calla-The-Wind-Through-The-Keyhole-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/6091092094098093/Green-Horse-Winter-The-Green-Horse-Hotel-2-by-Isolde-Pullum.pdf
    • http://loaminoo.linkpc.net/1090097099099090095/Death-by-a-Dark-Horse-Thea-Campbell-Mysteries-1-by-Susan-Schreye