Malicious PDF — malware analysis report

Static analysis result for SHA-256 8083a54a6bada19b…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 09:00:29 +01:00 Authoring application: mPDF 5.7
MD5: 524054b0a1b14a106e19df43b8a2459b SHA-1: af952c4d1bbe357b3b90f749b820374e737bea51 SHA-256: 8083a54a6bada19b5a149b19a57c1c470f8af97d6ecedb263f58072f86c8773d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links, such as http://loaminoo.linkpc.net/1090093099093095/Galen-Beknighted-Dragonlance-Heroes-6-Heroes-II-3-by-Michael-Williams.pdf, are likely intended to direct users to malicious or deceptive content. The document body, though partially corrupted, also contains these URLs, reinforcing the link-farming attack pattern.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090093099093095/Galen-Beknighted-Dragonlance-Heroes-6-Heroes-II-3-by-Michael-Williams.pdf
    • http://loaminoo.linkpc.net/1090093098090090/The-Gates-of-Thorbardin-Dragonlance-Heroes-5-Heroes-II-2-by-Dan-Parkinson.pdf
    • http://loaminoo.linkpc.net/1090093098097091/Kaz-the-Minotaur-Dragonlance-Heroes-4-Heroes-II-1-by-Richard-A-Knaak.pdf
    • http://loaminoo.linkpc.net/3093094092093097/The-New-Heroes-Superhuman-New-Heroes-Quantum-Prophecy-3-5-by-Michael--Carroll.pdf
    • http://loaminoo.linkpc.net/1090093096094096/Stormblade-Dragonlance-Heroes-2-by-Nancy-Varian-Berberick.pdf
    • http://loaminoo.linkpc.net/9098094091090/Uncommon-Heroes-A-Celebration-of-Heroes-and-Role-Models-for-Gay-and-Lesbian-Americans-by-Jeane-Manford.pdf
    • http://loaminoo.linkpc.net/1095094095099092/Ex-Heroes-Ex-Heroes-1-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/1090094099098090/The-Oath-and-the-Measure-Dragonlance-Meetings-Sextet-4-by-Michael-Williams.pdf
    • http://loaminoo.linkpc.net/3091093091098095/The-Heroes-of-Olympus-Books-1-4-CD-Audiobook-Bundle-The-Heroes-of-Olympus-1-4-by-Rick-Riordan.pdf
    • http://loaminoo.linkpc.net/4096097090093099/The-Heroes-of-Olympus-Paperback-3-Book-Boxed-Set-The-Heroes-of-Olympus-1-3-by-Rick-Riordan.pdf
    • http://loaminoo.linkpc.net/9092099097092090/Sakkara-The-New-Heroes-Quantum-Prophecy-2-by-Michael--Carroll.pdf
    • http://loaminoo.linkpc.net/7097098099094/The-Gathering-The-New-Heroes-Quantum-Prophecy-2-by-Michael--Carroll.pdf
    • http://loaminoo.linkpc.net/1091096094096090/The-Reckoning-The-New-Heroes-Quantum-Prophecy-3-by-Michael--Carroll.pdf
    • http://loaminoo.linkpc.net/1090096091099096097/Heroes-of-the-Faith-Dietrich-Bonhoeffer-by-Michael-Van-Dyke.pdf
    • http://loaminoo.linkpc.net/1092096091092090/No-More-Heroes-Heroes-1-by-Roo-I-MacLeod.pdf
    • http://loaminoo.linkpc.net/1091090094098094/In-the-Company-of-Heroes-The-Personal-Story-Behind-Black-Hawk-Down-by-Michael-J-Durant.pdf
    • http://loaminoo.linkpc.net/9091096091094093/Legion-of-Super-Heroes-1994--97-Legion-of-Super-Heroes-1994--by-Tom-McCraw.pdf
    • http://loaminoo.linkpc.net/4096095097097098/The-Last-Heroes-Men-At-War-1-by-W-E-B-Griffin.pdf
    • http://loaminoo.linkpc.net/4095097096092092/A-Need-for-Heroes-by-James-Cox.pdf
    • http://loaminoo.linkpc.net/7091097097098093/The-Heroes-by-Charles-Kingsley.pdf
    • http://loaminoo.linkpc.net/3091093091098095