Malicious PDF — malware analysis report

Static analysis result for SHA-256 df490a42289d7bc0…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 08:07:32 +01:00 Authoring application: mPDF 5.7
MD5: 677abde14d606334e38630676a40e79e SHA-1: b0b105c76765e13472687554b930834cfdee5526 SHA-256: df490a42289d7bc027308bd4fd9f38fa2dda392231c209cff6b411f7cc53b7ae
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a link farm, with 22 embedded external links. The document body is heavily obfuscated and unreadable, but the presence of numerous links to external PDFs, many with numeric slugs, suggests a tactic to artificially inflate search engine rankings or distribute potentially malicious content. The links themselves are currently marked as benign, but the pattern is suspicious.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5098099098090095/Hunter-x-Hunter-Vol-19-Hunter-x-Hunter-19-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098091094/Hunter-x-Hunter-Vol-28-Hunter-x-Hunter-28-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/3099092090096/Hunter-x-Hunter-Vol-01-Hunter-x-Hunter-1-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098091093/Hunter-x-Hunter-Vol-27-Hunter-x-Hunter-27-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098097090/Hunter-x-Hunter-Vol-23-Hunter-x-Hunter-23-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/1097096092099093/Hunter-x-Hunter-Vol-14-The-Secret-of-Greed-Island-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/3098099094093/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1093095091098095/Redemption-Dark-Hunter-20-5-Dream-Hunter-5-5-Were-Hunter-6-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/3090091091091095/Dark-Bites-Dream-Hunter-1-Hellchaser-1-Were-Hunter-1-Dark-Hunter-2-5-2-6-7-5-9-5-9-6-10-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1096094099091096/Bad-Moon-Rising-Dark-Hunter-18-Were-Hunter-4-Hellchaser-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/4096098092094/Upon-the-Midnight-Clear-Dark-Hunter-12-Dream-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/2091092093094090/Hunter-s-War-Legend-of-the-Wild-Hunter-Book-4-by-Garry-Spoor.pdf
    • http://loaminoo.linkpc.net/4093099092096097/The-Immortal-Hunter-Argeneau-11-Rogue-Hunter-2-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/3097097097096/The-Renegade-Hunter-Argeneau-12-Rogue-Hunter-3-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/4091095099097/The-Immortal-Hunter-Argeneau-11-Rogue-Hunter-2-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/2098095093091095/The-Renegade-Hunter-Argeneau-12-Rogue-Hunter-3-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/2098090098094096/Unleash-the-Night-Dark-Hunter-9-Were-Hunter-4-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1099092090091093/The-Guardian-Dream-Hunter-5-Were-Hunter-9-Hellchaser-4-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/2094098092093091/The-Hunter-Robert-Hunter-Series-0-5-by-Chris-Carter.pdf
    • http://loaminoo.linkpc.net/9096096098090/Hunter-The-Hunter-Saga-1-by-Sarai-Henderson.pdf
    • http://loaminoo.linkpc.net/1093095