Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d4fcb234e69b8e…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 03:46:58 +01:00 Authoring application: mPDF 5.7
MD5: 3b19f230b218132d1640ae4b58a90cca SHA-1: 05904d9a313849a227d8a29fdbcecf92a4794769 SHA-256: d9d4fcb234e69b8efd20da8da8885a3ddd0b4e43f5c8646a08cc5931b9e6a121
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF files hosted on the same domain, suggesting a link farm or a method to distribute malicious content disguised as legitimate documents. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure. The primary attack pattern observed is the deceptive use of embedded links within a PDF.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091091098090097095/Innocent-Traitor-A-Novel-of-Lady-Jane-Grey-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3090095092092096/The-Lady-Elizabeth-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/1090093097098091/A-Dangerous-Inheritance-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3099091098097/Eleanor-of-Aquitaine-A-Life-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3094096092096/The-Six-Wives-of-Henry-VIII-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/2090098098093098/Captive-Queen-A-Novel-of-Eleanor-of-Aquitaine-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3097098095098094/Eleanor-of-Aquitaine-By-the-Wrath-of-God-Queen-of-England-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3092096090/Katherine-of-Arag-n-The-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/5097094092/Anne-Boleyn-A-King-s-Obsession-Six-Tudor-Queens-2-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/1097098093091095/Anne-Boleyn-A-King-s-Obsession-Six-Tudor-Queens-2-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/2096091092096093/Katherine-of-Aragon-the-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3091098093097097/Katherine-of-Aragon-The-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3098096092090097/Mistress-of-the-Monarchy-The-Life-of-Katherine-Swynford-Duchess-of-Lancaster-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3097095099098091/Against-Our-Better-Judgment-The-Hidden-History-of-How-the-United-States-Was-Used-to-Create-Israel-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3091090098091096/innocent-hungry-The-innocent-recipe-book-for-filling-your-family-with-good-stuff-by-Innocent.pdf
    • http://loaminoo.linkpc.net/7092092091093096/Queens-of-the-Conquest-England-s-Medieval-Queens-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3093099095098091/Elizabeth-the-Queen-The-Lady-Elizabeth-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/8098097092098099/Six-Tudor-Queens-Writing-a-New-Story-Six-Tudor-Queens-0-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/8095092090/The-Traitor-s-Ruin-The-Traitor-s-Circle-2-by-Erin-Beaty.pdf
    • http://loaminoo.linkpc.net/4097098096090093/The-Innocent-Betrayal-Innocent-2-by-Victoria-Sue.pdf
    • http://loaminoo.linkpc.net/1097098093091095/Anne-Boleyn-A-King-s-Obsession-Six-Tudor-Queens-2-by-Alison-We