Malicious PDF — malware analysis report

Static analysis result for SHA-256 970ceebf76f16bbc…

MALICIOUS

PDF

18.2 KB Created: 2019-05-01 05:14:26 +01:00 Authoring application: mPDF 5.7
MD5: 47e957a814c29766b6cb092236fd8bbd SHA-1: 03ca01661f53803d756cab635e845612fee008c1 SHA-256: 970ceebf76f16bbc4da1b729f1b4aa3e060d2e07a2da62543cca5b457b030fb6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking documents, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to distribute further malware. The ClamAV detection as Pdf.Dropper.Agent-7157407-0 further supports its malicious classification. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7157407-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7157407-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8096096091090092/Bluthochdruck-Vorbeugen-erkennen-behandeln-by-Anke-Nolte.pdf
    • http://loaminoo.linkpc.net/8096096091090099/Mobbing-erkennen-ansprechen-vorbeugen-by-Hans-J-rgen-Kratz.pdf
    • http://loaminoo.linkpc.net/1090090096098096092/The-Nick-Nolte-Handbook---Everything-You-Need-to-Know-about-Nick-Nolte-by-Skyler-Koch.pdf
    • http://loaminoo.linkpc.net/1090090097090094095/ISLE-Work-The-Collected-Works-of-James-Stuart-Nolte-by-James-Stuart-Nolte.pdf
    • http://loaminoo.linkpc.net/1090093093095098095/Autoimmunerkrankungen-mit-chinesischer-Medizin-gezielt-behandeln-by-Wanzhu-Hou.pdf
    • http://loaminoo.linkpc.net/1091097093094096090/Bluthochdruck-bei-Frauen---ein-untersch-tztes-Risiko-by-Lutz-Koch.pdf
    • http://loaminoo.linkpc.net/1091096099097096094/Depression-Burn-out-Bluthochdruck-Dreimal-t-glich-streicheln-Tier-Ratgeber-by-Imre-Kusztrich.pdf
    • http://loaminoo.linkpc.net/7095091094098090/Art-Nouveau-by-Anke-von-Heyl.pdf
    • http://loaminoo.linkpc.net/1099093091094097/Bruises-by-Anke-de-Vries.pdf
    • http://loaminoo.linkpc.net/1091093097094096090/Gesch-ftsessen-meistern-by-Anke-Quittschau.pdf
    • http://loaminoo.linkpc.net/1090092097090099097/F-hrung-im-Klassenzimmer-Disziplinschwierigkeiten-und-sozialen-St-rungen-vorbeugen-und-effektiv-begegnen---ein-Leitfaden-f-r-Miteinander-im-Unterricht-by-Beate-Schuster.pdf
    • http://loaminoo.linkpc.net/1090090093097093090/Soziale-Grundrechte-in-Den-Landesverfassungen-by-Anke-Brenne.pdf
    • http://loaminoo.linkpc.net/8098093093099093/Vil-m-Flusser-An-Introduction-by-Anke-K-Finger.pdf
    • http://loaminoo.linkpc.net/1090098093098097097/Das-Haus-hinter-dem-Deich-Roman-by-Anke-Cibach.pdf
    • http://loaminoo.linkpc.net/8096096090091093/Waldsch-den-Erkennen-by-Bernhard-Hanisch.pdf
    • http://loaminoo.linkpc.net/1090092094096096095/Charlotte-Roches--Feuchtgebiete--Ekel-Und-Sexualitat-ALS-Tabus-in-Den-Medien-by-Anke-Mirja-Dahlmann.pdf
    • http://loaminoo.linkpc.net/9090099099091097/Kompetenzen-Erkennen-Bilanzieren-Und-Entwickeln-by-Volker-Heyse.pdf
    • http://loaminoo.linkpc.net/8096096090093099/Histamin-Intoleranz-erkennen-und-therapieren-by-Manuela-Str-hle.pdf
    • http://loaminoo.linkpc.net/8096096090099096/Schlaganfall-Erkennen---Rehabilitation---Vorbeugung-by-Michael-Hessinger.pdf
    • http://loaminoo.linkpc.net/1090092097097091098/Erkennen-Und-Erinnern-in-Kunst-Und-Literatur-by-Wolfgang-Fr-hwald.pdf
    • http://loaminoo.linkpc.net/1091096099097096094/Depression-Burn-out-Bluthochdruck-Dreimal-t-glich-streicheln-Tier-Ratg