Malicious PDF — malware analysis report

Static analysis result for SHA-256 cbd64a3c6dfb2d18…

MALICIOUS

PDF

21.4 KB Created: 2019-05-02 17:49:20 +01:00 Authoring application: mPDF 5.7
MD5: 82d5328337b795cdc4a5774ba38452dc SHA-1: 810da35d9c73080747c362143266618bd4881f7e SHA-256: cbd64a3c6dfb2d183fb142e3200597642f4bccf5a9647cd6be70893bb705f285
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents. These links are hosted on a dynamic DNS domain, suggesting a link farm or redirection scheme. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with numerous external links, pointing towards a deceptive or malicious intent to drive traffic to these external resources. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7090098094/Cadmium-Dragon-Dragon-Guard-of-Drakkaris-2-by-Terry-Bolryder.pdf
    • http://loaminoo.linkpc.net/5095093097/Steel-Rent-a-Dragon-1-by-Terry-Bolryder.pdf
    • http://loaminoo.linkpc.net/3090092094098093/Only-for-Her-Dragon-Dragon-Guard-6-by-Julia-Mills.pdf
    • http://loaminoo.linkpc.net/3097094092096097/G-A-Aiken-Dragon-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-Last-Dragon-Standing-amp-How-to-Drive-a-Dragon-Crazy-The-Dragon-Kin-3-6-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/4099093097095099/Dragon-Prince-Series-Including-Melanie-Rawn-Dragon-Prince-Sunrunner-s-Fire-the-Star-Scroll-Sunrunner-High-Prince-Stronghold-Novel-the-Dragon-Token-Skybowl-Dragon-Prince-and-Dragon-Star-Trilogies-Diarmadhi-Merida-Dragon-Prince-Isulk-im-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/2093094098099091/Call-of-the-Dragon-a-Dragon-Fantasy-Adventure-Dragon-Riders-of-Elantia-Book-1-by-Jessica-Drake.pdf
    • http://loaminoo.linkpc.net/1091094097090097099/Asher-Dragon-Guard-Berserkers-2-by-Julia-Mills.pdf
    • http://loaminoo.linkpc.net/8097095092096091/G-A-Aiken-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-amp-Last-Dragon-Standing-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/1091096095094097/Nickerbacher-The-Funniest-Dragon-by-Terry-John-Barto.pdf
    • http://loaminoo.linkpc.net/6097098096098092/The-Blue-Dragon-A-Claire-Agon-Dragon-Book-Claire-Agon-Dragon-1-by-Salvador-Mercer.pdf
    • http://loaminoo.linkpc.net/1090098099093094098/Searching-Dragon-Dragon-Rising-Urban-Fantasy-Series-2-by-Trudi-Jaye.pdf
    • http://loaminoo.linkpc.net/4092097095097095/The-Billionaire-Dragon-Shifter-s-Mate-Gray-s-Hollow-Dragon-Shifters-1-by-Zoe-Chant.pdf
    • http://loaminoo.linkpc.net/4091095095098/Dragon-of-Legend-Destiny-Fantasy-Dragon-Adventure-by-Angelika-Meyer.pdf
    • http://loaminoo.linkpc.net/2091094090090092/Dragon-in-My-Yard-The-Stone-Dragon-Saga-Volume-2-by-Elizabeth-S-Tyree.pdf
    • http://loaminoo.linkpc.net/1091098091097090093/Dragon-Pawns-Jules-and-the-Runt-Dragon-by-William-Hill.pdf
    • http://loaminoo.linkpc.net/2095094092095090/The-Old-Dragon-of-the-Mountain-s-Christmas-Dragon-Lords-of-Valdier-9-by-S-E-Smith.pdf
    • http://loaminoo.linkpc.net/4099099097095095/Triumph-of-the-Dragon-Brothers-of-the-Dragon-3-by-Robin-Wayne-Bailey.pdf
    • http://loaminoo.linkpc.net/2093093099095093/The-Dragon-Scale-Lute-Daughter-of-the-Dragon-Throne-1-by-J-C-Kang.pdf
    • http://loaminoo.linkpc.net/7099094097095/How-to-Betray-a-Dragon-s-Hero-How-to-Train-Your-Dragon-11-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/2095094095095090/Wicked-Dark-Dragon-Dragon-Heat-3-by-Lolita-Lopez.pdf
    • http://loaminoo.linkpc.net/2093094098099091/Call-of-the-Dragon-a-Dragon-Fantasy-Adventure-Dragon-Riders-of-Elantia-Book-1-by-