Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4172fb670195514…

MALICIOUS

PDF

15.7 KB Created: 2019-04-30 18:01:21 +01:00 Authoring application: mPDF 5.7
MD5: 7fe2fbd0bbc8886be76cd18641ec2aee SHA-1: 24d0aa64af9de266741e144e523b13d165990c19 SHA-256: c4172fb67019551433d9268e1f45825313aae611847b617e7debf5bc5b5e2ae4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a multitude of external sites. No scripts were extracted from this sample, and the document body was heavily corrupted, limiting further analysis of the exact user-facing lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093098095098092/The-Wolf-Almanac-by-Robert-H-Busch.pdf
    • http://loaminoo.linkpc.net/8099093095099092/David-Busch-s-Quick-Snap-Guide-to-Using-Digital-SLR-Lenses-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093094099097/David-Busch-s-Nikon-D3200-Guide-to-Digital-Slr-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/6099093090094099/David-Busch-s-Sony-Alpha-Nex-5N-Guide-to-Digital-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/6099093090095091/David-Busch-s-Sony-Alpha-Slt-A65-Guide-to-Digital-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093095097099/David-Busch-s-Nikon-D3100-Guide-to-Digital-Slr-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093095098093/David-Busch-s-Digital-Infrared-Pro-Secrets-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/3090093096097093/Son-of-the-White-Wolf-by-Robert-E-Howard.pdf
    • http://loaminoo.linkpc.net/8099093095097098/The-Worlds-of-Matt-Busch-by-Matt-Busch.pdf
    • http://loaminoo.linkpc.net/4092097095096099/New-Scotia-Pack-Box-Set-Shield-Wolf-Wolf-Lover-Fire-Wolf-by-Victoria-Danann.pdf
    • http://loaminoo.linkpc.net/2092099096092094/The-Red-Wolf-Conspiracy-The-Chathrand-Voyage-1-by-Robert-V-S-Redick.pdf
    • http://loaminoo.linkpc.net/9094095090090093/WOLF-S-HOUR-Band-1-Die-Verwandlung-by-Robert-R-McCammon.pdf
    • http://loaminoo.linkpc.net/4091097097094091/The-Red-Wolf-Conspiracy-Chathrand-Voyages-1-by-Robert-V-S-Redick.pdf
    • http://loaminoo.linkpc.net/1091094093093091098/Kopfaktschn-Im-Club-Der-Einsamen-Herzen-Stucke-Und-Materialien-by-Robert-Wolf.pdf
    • http://loaminoo.linkpc.net/1091094098098096095/Art-Of-The-Middle-Ages-Translated-From-German-By-Robert-Erich-Wolf-by-HANS-HELMUT-HOFSTATTER.pdf
    • http://loaminoo.linkpc.net/1098091094/Wolf-by-Wolf-Wolf-by-Wolf-1-by-Ryan-Graudin.pdf
    • http://loaminoo.linkpc.net/3090099097094097/The-Mother-s-Almanac-by-Marguerite-Kelly.pdf
    • http://loaminoo.linkpc.net/1090092098096090093/The-Malt-Whisky-Almanac-by-Wallace-Milroy.pdf
    • http://loaminoo.linkpc.net/4098097090097/Almanac-of-Words-at-Play-by-Willard-R-Espy.pdf
    • http://loaminoo.linkpc.net/1091091095096098098/Boneshaker-A-Bicycling-Almanac-BA-43-500-10-by-Evan-P-Schneider.pdf
    • http://loaminoo.linkpc.net/4092097095096099/New-Scotia-Pack-Box-Set-Shield-Wolf-Wolf-Lover-Fire-Wo