Malicious PDF — malware analysis report

Static analysis result for SHA-256 da56c484b23ff761…

MALICIOUS

PDF

13.2 KB Created: 2019-04-30 03:16:57 +01:00 Authoring application: mPDF 5.7
MD5: 4bda49eab76ffc5a821047d7e33ccbb9 SHA-1: 1b9c7af1135eb862b06077be4ea3788193cbcfc7 SHA-256: da56c484b23ff761b7cde02a59c270412e29013f74c9eaa365c6a289539c3da8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm. While the extracted URLs are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users to potentially harmful content or to game search engine rankings. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097094096090098/Hermes-Reports-by-Cinna-The-Poet.pdf
    • http://loaminoo.linkpc.net/1099090093094/The-Lunatic-the-Lover-and-the-Poet-by-Myrlin-A-Hermes.pdf
    • http://loaminoo.linkpc.net/7097094095099098/I-Cinna-by-Tim-Crouch.pdf
    • http://loaminoo.linkpc.net/7097094095099094/Corneille-Cinna-by-C-J-Gossip.pdf
    • http://loaminoo.linkpc.net/7097094095099095/Cinna-by-Kitina-Thomas.pdf
    • http://loaminoo.linkpc.net/7097094095099097/Le-Cid-Cinna-Polyeuct-by-Pierre-Corneille.pdf
    • http://loaminoo.linkpc.net/7097094096090092/The-Cid-Cinna-The-Theatrical-Illusion-by-Pierre-Corneill.pdf
    • http://loaminoo.linkpc.net/4090091099098092/Nobody-s-Fault-by-Patricia-Hermes.pdf
    • http://loaminoo.linkpc.net/7097094097091091/The-Road-to-Total-Earthquake-Safety-by-Cinna-Lomnitz.pdf
    • http://loaminoo.linkpc.net/4098099092097092/Hermes-3000-by-William-Kotzwinkle.pdf
    • http://loaminoo.linkpc.net/2097096093095/You-Shouldn-t-Have-to-Say-Goodbye-by-Patricia-Hermes.pdf
    • http://loaminoo.linkpc.net/8095091090096097/Zeus-and-Roxanne-by-Patricia-Hermes.pdf
    • http://loaminoo.linkpc.net/8090090095091098/Alimentation-Animale-by-Othniel-Hermes.pdf
    • http://loaminoo.linkpc.net/9099095096091095/The-Corpus-Hermetica-by-Hermes-Trismestigustus.pdf
    • http://loaminoo.linkpc.net/1091098096097090099/Holding-on-to-Hope-by-Kathryn-J-Hermes.pdf
    • http://loaminoo.linkpc.net/7097094097090099/The-Death-of-Eliyah-Out-of-History-Gods-Inc-Book-1-by-Cinna-Moon.pdf
    • http://loaminoo.linkpc.net/3092090097099090/Hermes-the-Thief-The-Evolution-of-a-Myth-by-Norman-O-Brown.pdf
    • http://loaminoo.linkpc.net/8097094096093095/Hermes-the-Highwayman-Greek-Gods-in-Greatcoats-Book-3-by-R-J-Steele.pdf
    • http://loaminoo.linkpc.net/2090099093092093/Inner-Peace-Wisdom-from-Jean-Pierre-de-Caussade-by-Kathryn-J-Hermes.pdf
    • http://loaminoo.linkpc.net/3093096091094093/Bloodshot-The-Cheshire-Red-Reports-1-by-Cherie-Priest.pdf
    • http://loaminoo.linkpc.net/