Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8f8b3ec51f84535…

MALICIOUS

PDF

15.2 KB Created: 2019-04-30 04:23:19 +01:00 Authoring application: mPDF 5.7
MD5: 82f2039d00288ff9409465e40bc792bc SHA-1: d4f79761224b65435e9d1904e83901a7f865891e SHA-256: c8f8b3ec51f845355a6a8dcfa6aed30c90edb99c8e9b7e4d096c2bb9cc1b7048
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is likely for SEO manipulation or to distribute further malicious content. While the document body is heavily obfuscated, the presence of numerous links to external PDFs suggests a delivery mechanism rather than direct user interaction with the document content itself. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5091096093099099/Blessed-City-The-Letters-Of-Gwen-Harwood-To-Thomas-Riddell-by-Gwen-Harwood.pdf
    • http://loaminoo.linkpc.net/1091092093097091094/Spider-Gwen-Vol-6-The-Life-of-Gwen-Stacy-by-Jason-Latour.pdf
    • http://loaminoo.linkpc.net/9092090099099/The-Seance-by-John-Harwood.pdf
    • http://loaminoo.linkpc.net/8099091092099/The-Seance-by-John-Harwood.pdf
    • http://loaminoo.linkpc.net/4098097098093/The-Ghost-Writer-by-John-Harwood.pdf
    • http://loaminoo.linkpc.net/1095090098094095/Impossible-Saints-by-Clarissa-Harwood.pdf
    • http://loaminoo.linkpc.net/7093094092094097/The-Shuttered-Room-by-Charles-Jay-Harwood.pdf
    • http://loaminoo.linkpc.net/5091096093096097/Articles-of-Faith-by-Ronald-Harwood.pdf
    • http://loaminoo.linkpc.net/2090098096098093/Young-Junius-by-Seth-Harwood.pdf
    • http://loaminoo.linkpc.net/2095099090096090/Descending-Gina-Harwood-2-by-Indi-Martin.pdf
    • http://loaminoo.linkpc.net/4094094091099099/Triumph-Collected-Stories-by-Lizzie-Harwood.pdf
    • http://loaminoo.linkpc.net/4097095094095096/Czechmate-Jack-Palms-3-by-Seth-Harwood.pdf
    • http://loaminoo.linkpc.net/1093091091094098/This-Is-Life-Jack-Palms-2-by-Seth-Harwood.pdf
    • http://loaminoo.linkpc.net/2099098096092091/Davy-Harwood-The-Immortal-Prophecy-1-by-Tijan.pdf
    • http://loaminoo.linkpc.net/1090098097098094097/Into-Dreams-Gina-Harwood-3-by-Indi-Martin.pdf
    • http://loaminoo.linkpc.net/2092093091098098/Romeo-for-Real-by-Markus-Harwood-Jones.pdf
    • http://loaminoo.linkpc.net/4092091099097090/Xamnesia-Everything-I-Forgot-in-my-Search-for-an-Unreal-Life-by-Lizzie-Harwood.pdf
    • http://loaminoo.linkpc.net/1092090090092093/Xamnesia-Everything-I-Forgot-in-my-Search-for-an-Unreal-Life-by-Lizzie-Harwood.pdf
    • http://loaminoo.linkpc.net/3095091097092099/Birth-of-a-New-Brain-Healing-from-Postpartum-Bipolar-Disorder-by-Dyane-Harwood.pdf
    • http://loaminoo.linkpc.net/1091095096099094098/Hitler-s-War-World-War-II-as-Portrayed-by-Signal-the-International-Nazi-Propaganda-Magazine-by-Jeremy-Harwood.pdf
    • http://loaminoo.linkpc.net/4097095094095096/Czechmat