Malicious PDF — malware analysis report

Static analysis result for SHA-256 975fa0d66eb4a32c…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 19:27:30 +01:00 Authoring application: mPDF 5.7
MD5: 686f7f9fb671e60f701ed96834d1f269 SHA-1: 39dbdc2d26b4d0b8523ddab4928947e4f75a9c9c SHA-256: 975fa0d66eb4a32c669759ce511afec2fe6926106afce913a0711a47028f5fef
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, constituting a link farm. This technique is often used to artificially inflate search engine rankings or to distribute malicious content indirectly. The primary heuristic indicates a critical finding related to this link farm behavior. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091098098095093/Werewolves-of-Chernobyl-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/4094092097093/The-Truth-About-Chernobyl-by-Grigori-Medvedev.pdf
    • http://loaminoo.linkpc.net/1092096090091098/Chernobyl-Werewolf-Team-Greywolf-Series-2-by-Eva-Gordon.pdf
    • http://loaminoo.linkpc.net/1090092097095091097/Chernobyl-Murders-Lazlo-Horvath-Thriller-1-by-Michael-Beres.pdf
    • http://loaminoo.linkpc.net/4094097090096091/Wormwood-Forest-A-Natural-History-of-Chernobyl-by-Mary-Mycio.pdf
    • http://loaminoo.linkpc.net/5098095098093/Chernobyl-s-Wild-Kingdom-Life-in-the-Dead-Zone-by-Rebecca-L-Johnson.pdf
    • http://loaminoo.linkpc.net/1097098095098098/Visit-Sunny-Chernobyl-And-Other-Adventures-in-the-World-s-Most-Polluted-Places-by-Andrew-Blackwell.pdf
    • http://loaminoo.linkpc.net/1096090095090099/Clown-d-XXX-d-1-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/1096090096098093/Mr-Jaguar-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/3093098090092094/Don-t-Go-There-From-Chernobyl-to-North-Korea-one-man-s-quest-to-lose-himself-and-find-everyone-else-in-the-world-s-strangest-places-by-Adam-Fletcher.pdf
    • http://loaminoo.linkpc.net/1096090097091097/Rainbow-Bash-d-XXX-d-2-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/3095093093096090/Scavengers-Collection-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/4098090098090094/Scavengers-Collection-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/1092090094093091/All-Strings-Attached-by-Miss-Merikan.pdf
    • http://loaminoo.linkpc.net/2093094093095090/Diary-of-a-Teenage-Taxidermist-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/4097099090093091/Laurent-and-the-Beast-Kings-of-Hell-MC-1-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/1097097094092096/Red-Hot-Coffin-Nails-MC-California-Sex-amp-Mayhem-5-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/2092098097091093/Bare-Knuckle-Love-Rabid-Mongrels-MC-1-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/9094090093093099/Pfad-ohne-Wiederkehr---Hounds-of-Valhalla-MC-Sex-amp-Mayhem-DE-3-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/1099092097099094/His-Favorite-Color-Is-Blood-Coffin-Nails-MC-Sex-amp-Mayhem-8-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/3093098090092094/Don-t-Go-There-From-Chernobyl-to-