Malicious PDF — malware analysis report

Static analysis result for SHA-256 9674156566d70814…

MALICIOUS

PDF

30.3 KB Created: 2019-04-30 02:56:37 +01:00 Authoring application: mPDF 5.7
MD5: 4fdfb769eac636ba7b3be38bcd9fea71 SHA-1: 1fbafcc8737bcc445fb6fa51446c2d348ca3aa92 SHA-256: 9674156566d708143f217f39d8307700a420fab5b6cc0ca5fddcfe38b59d6d5f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 32 numeric slug SEO PDF links. While the document body is heavily obfuscated, the presence of numerous external links suggests a redirection or phishing attempt. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093097093091099/Lgbt-Activism-and-the-Making-of-Europe-A-Rainbow-Europe-by-Phillip-Ayoub.pdf
    • http://loaminoo.linkpc.net/1091093097092094094/When-States-Come-Out-Europe-s-Sexual-Minorities-and-the-Politics-of-Visibility-by-Phillip-M-Ayoub.pdf
    • http://loaminoo.linkpc.net/5099092098097091/Migrations-et-mobilit-s-en-Europe-Politiques-publiques-et-perspectives-dint-gration-1992-2012-Dynamiques-citoyennes-en-Europe-Citizenship-Dynamics-in-Europe-t-5-by-Paul-Lees.pdf
    • http://loaminoo.linkpc.net/9092094093095094/Transcultural-Europe-Cultural-Policy-in-a-Changing-Europe-by-Ulrike-Hanna-Meinhof.pdf
    • http://loaminoo.linkpc.net/1096091097094094/The-Ghosts-of-Europe-Central-Europe-s-Past-and-Uncertain-Future-by-Anna-Porter.pdf
    • http://loaminoo.linkpc.net/5099093098091093/Les-Soupirs-de-L-Europe-Etc-Or-the-Groans-of-Europe-at-the-Prospect-of-the-Present-Posture-of-Affairs-In-a-Letter-by-Jean-Dumont.pdf
    • http://loaminoo.linkpc.net/5099093097095097/Les-Soupirs-de-L-Europe-Or-the-Groans-of-Europe-at-the-Prospect-of-the-Present-Posture-of-Affairs-by-Jean-De-Carlscroon-Dumont.pdf
    • http://loaminoo.linkpc.net/1092091098092092/Europe-In-Autumn-Fractured-Europe-Sequence-1-by-Dave-Hutchinson.pdf
    • http://loaminoo.linkpc.net/5090097095092098/The-Arming-of-Europe-and-the-Making-of-the-First-World-War-by-David-G-Herrmann.pdf
    • http://loaminoo.linkpc.net/6098095095097090/The-Germanic-Invasions-The-Making-of-Europe-400-600-A-D-by-Lucien-Musset.pdf
    • http://loaminoo.linkpc.net/7098090096091099/2015-EUROPE-S-BEST-PSYCHICS-AND-MEDIUMS-Meilleurs-M-diums-et-Voyants-en-France-et-Europe-by-Jean-Maximillien-De-La-Croix-de-Lafayette.pdf
    • http://loaminoo.linkpc.net/8099090094098093/Reliable-Software-Technologies---ADA-Europe-2009-14th-ADA-Europe-International-Conference-Brest-France-June-8-12-2009-Proceedings-by-Fabrice-Kordon.pdf
    • http://loaminoo.linkpc.net/6095091095095090/The-Making-of-Europe-s-Critical-Infrastructure-Common-Connections-and-Shared-Vulnerabilities-by-Per-Hogselius.pdf
    • http://loaminoo.linkpc.net/6095091095091098/Making-of-Europe-s-Critical-Infrastructure-by-Kaijser-Arne-Vleuten-Erik-Van-Der-Hoegselius-Per-Hommels-Anique.pdf
    • http://loaminoo.linkpc.net/7098090096092091/Volume-I-2016-Europe-s-Best-Psychics-And-Mediums-2016-Meilleurs-Voyants-et-M-diums-de-France-et-d-Europe-by-Jean-Maximillien-De-La-Croix-de-Lafayette.pdf
    • http://loaminoo.linkpc.net/5094095099096098/Governing-Shale-Gas-Development-Citizen-Participation-and-Decision-Making-in-the-Us-Canada-Australia-and-Europe-by-John-Whitton.pdf
    • http://loaminoo.linkpc.net/8094095095096095/Yearbook-of-the-European-Convention-for-the-Prevention-of-Torture-and-Inhuman-or-Degrading-Treatment-or-Punishment-Annuaire-de-la-Convention-Europ-enne-Pour-La-Pr-vention-de-la-Torture-Et-Des-Peines-Ou-Traitements-Inhumains-Ou-D-gradants-Volume-20-2011-by-Council-of-Europe-Conseil-de-L-39-Europe.pdf
    • http://loaminoo.linkpc.net/5097097091090094/Rainbow-Warriors-pisode-1-Comment-une-arm-e-de-LGBT-renverse-une-dictature-africaine-by-Ayerdhal.pdf
    • http://loaminoo.linkpc.net/6095093093093093/SGI-President-Ikeda-in-Europe-SGI-President-Ikeda-in-Europe-1-by-Daisaku-Ikeda.pdf
    • http://loaminoo.linkpc.net/9092092093096099/One-Man-Against-Europe-by-Konrad-Heiden.pdf
    • http://loaminoo.linkpc.net/1096091097094094/The-Ghosts-of-Europe-Central-Europe-s-