Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb5fc93d598deec8…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 03:58:04 +01:00 Authoring application: mPDF 5.7
MD5: 6ce6af953fc931942d5bcd989c99151f SHA-1: 7c65001f5fe46e5b2834e32e5a0a138b7e66de4b SHA-256: cb5fc93d598deec8f8fb0c6506bde7120e3714f08456e4d281845d6b5733dd49
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093095099092/The-Ghost-in-the-Tokaido-Inn-Samurai-Detective-1-by-Dorothy-Hoobler.pdf
    • http://loaminoo.linkpc.net/4097096098099096/Ghost-Girl-The-Detective-s-Daughter-2-by-Lesley-Thomson.pdf
    • http://loaminoo.linkpc.net/1090099093090091095/Samurai-Revolution-The-Dawn-of-Modern-Japan-Seen-Through-the-Eyes-of-the-Shogun-s-Last-Samurai-by-Romulus-Hillsborough.pdf
    • http://loaminoo.linkpc.net/5091091090097098/Tokaido-Road-by-Nancy-Gaffield.pdf
    • http://loaminoo.linkpc.net/9093095093099096/Hiroshige-s-Tokaido-in-Prints-and-Poetry-by-Reiko-Chiba.pdf
    • http://loaminoo.linkpc.net/8094091099094097/Zonk-The-Dreaming-Tortoise-by-David-Hoobler.pdf
    • http://loaminoo.linkpc.net/8094091099095091/Zonk-and-the-Gray-Whales-Birthday-Party-by-David-Hoobler.pdf
    • http://loaminoo.linkpc.net/3098093092098095/The-Grand-Genius-Summer-of-Henry-Hoobler-by-Lisa-Shanahan.pdf
    • http://loaminoo.linkpc.net/1091097097098092/Samurai-Awakening-Samurai-Awakening-1-by-Benjamin-Martin.pdf
    • http://loaminoo.linkpc.net/1098090098092095/Alaska-and-Back-With-Dave-and-Dorothy-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/4097096098099097/The-Detective-s-Secret-The-Detective-s-Daughter-3-by-Lesley-Thomson.pdf
    • http://loaminoo.linkpc.net/4097098098092096/His-American-Detective-Victorian-Gay-Detective-1-by-Summer-Devon.pdf
    • http://loaminoo.linkpc.net/4097098098093093/His-Scottish-Detective-Victorian-Gay-Detective-3-by-Summer-Devon.pdf
    • http://loaminoo.linkpc.net/9099097098/Dorothy-Must-Die-Dorothy-Must-Die-1-by-Danielle-Paige.pdf
    • http://loaminoo.linkpc.net/2098098095096099/The-Best-Ghost-Stories-1800-1849-A-Classic-Ghost-Anthology-by-Andrew-Barger.pdf
    • http://loaminoo.linkpc.net/3097095090097092/Ghost-a-la-Mode-A-Ghost-of-Granny-Apples-Mystery-1-by-Sue-Ann-Jaffarian.pdf
    • http://loaminoo.linkpc.net/1093098092092091/Here-Lies-The-Collected-Stories-of-Dorothy-Parker-by-Dorothy-Parker.pdf
    • http://loaminoo.linkpc.net/3096099091093/The-Case-of-the-Displaced-Detective-At-Speed-Displaced-Detective-2-by-Stephanie-Osborn.pdf
    • http://loaminoo.linkpc.net/3095093097096097/Giving-Up-the-Ghost-Laying-a-Ghost-2-by-Jane-Davitt.pdf
    • http://loaminoo.linkpc.net/1092094099096094/The-No-1-Ladies-Detective-Agency-Set-The-No-1-Ladies-Detective-Agency-Tears-of-the-Giraffe-Morality-for-Beautiful-Girls-The-Kalahari-Typing-School-For-Men-The-Full-Cupboard-of-Life-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net