Malicious PDF — malware analysis report

Static analysis result for SHA-256 df4782c6befbeab6…

MALICIOUS

PDF

21.7 KB Created: 2019-05-02 18:08:10 +01:00 Authoring application: mPDF 5.7
MD5: 43ac3c6206f222ceacc269a8301b737a SHA-1: 8c2fb876a71a0ec5d8477fc1b70996679d2640b0 SHA-256: df4782c6befbeab6b124e7fd09879082cb168ec912fef3b5e5e18bc6173deae3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a potential link farm or SEO poisoning attempt. No scripts were extracted from this sample. The primary attack pattern observed is the distribution of numerous external links within the document.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8098091092092096/Ein-Werwolf-zum-Lunch-Samantha-und-Tyler-Werwolf-Erotik-Ein-Werwolf-zum-2-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/1091092097092090098/Ein-Werwolf-zum-Dessert-amp-Ein-Werwolf-zum-Nachtisch-Sammelband-Teil-5-amp-6-Prickelnde-Gestaltwandler-Romance-Ein-Werwolf-zum-3-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/8098091092093093/Ein-Werwolf-zum-Tee-Philipp-amp-Rachel-Ein-Werwolf-zum-3-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/1091092097091094094/Ein-Werwolf-zum-Heiraten-Sammelband---Prickelnde-Gestaltwandler-Romance-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/8098091091095091/Twilight-Werwolf-by-Lady-Bluebell.pdf
    • http://loaminoo.linkpc.net/8098090099093099/The-Hero-As-Werwolf-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/8097091096093097/Das-magische-Amulett-92-Nachts-wenn-der-Werwolf-ruft-by-Jan-Gardemann.pdf
    • http://loaminoo.linkpc.net/8098091092093097/Schwule-Werwolf-Sexgeschichten-Die-Enth-llung-des-schwulen-Werwolfs-by-T-J-Schmitt.pdf
    • http://loaminoo.linkpc.net/9096092090094092/Wenn-Hexen-Vampire-bei-Vollmond-k-ssen-ist-der-Werwolf-sauer-by-Mia-Dako.pdf
    • http://loaminoo.linkpc.net/9096092090099098/Wenn-Hexen-Vampire-bei-Vollmond-k-ssen-ist-der-Werwolf-sauer-Gesamtausgabe-B-nde-1---3-by-Mia-Dako.pdf
    • http://loaminoo.linkpc.net/1090091094095099098/Mein-Boss-ist-ein-grantiger-Werwolf-und-ich-glaube-er-will-mich-fressen-by-Jane-Wallace-Knight.pdf
    • http://loaminoo.linkpc.net/9096092090094097/Hexen-Kuss-Liebes-Zauber-Werwolf-Fluch-Vollmond-Vampire-Sammelband-Teile-1-3-by-Tatana-Fedorovna.pdf
    • http://loaminoo.linkpc.net/9096092090094099/Hexen-Kuss-Gesamtausgabe-Teile-1-4-Liebes-Zauber-Werwolf-Fluch-Vollmond-Vampire-und-Herz-Klopfen-by-Tatana-Fedorovna.pdf
    • http://loaminoo.linkpc.net/1091092094099094099/S-ndige-N-chte-Die-Pr-fung-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/1091092097091094090/Kitty-Malone-Gestaltwandler-Romance-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/9099094095097094/Magisch-verf-hrt-2-sinnlich-prickelnde-Stories-by-Natalie-Salkin.pdf
    • http://loaminoo.linkpc.net/8098098092094092/Rotk-ppchen-und-der-b-se-Wolfgang---Samantha-Love-Erotik-amp-BDSM-Collection-by-Samantha-Love.pdf
    • http://loaminoo.linkpc.net/1090091093090096096/H-hepunkte-Edelster-Erotik---Vol-2-Edition-Edelste-Erotik-by-Valerie-Nilon.pdf
    • http://loaminoo.linkpc.net/1090091093090097094/H-hepunkte-Edelster-Erotik---Vol-4-Edition-Edelste-Erotik-by-Eva-Maria-Lamia.pdf
    • http://loaminoo.linkpc.net/3097092091093099/Lunch-Lady-and-the-Summer-Camp-Shakedown-Lunch-Lady-4-by-Jarrett-J-Krosoczka.pdf