Malicious PDF — malware analysis report

Static analysis result for SHA-256 e291adcead39e066…

MALICIOUS

PDF

23.6 KB Created: 2019-05-06 16:57:23 +01:00 Authoring application: mPDF 5.7
MD5: 93a969a8684cf9c215db3a3cf7e20809 SHA-1: a840c8d846ccdc78aa6175e584d8040bb27279bb SHA-256: e291adcead39e0667380757e7039ba07a7db0e450e964a6f819fc526072e2b2f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these links are likely intended to direct users to external PDF files. While the document body is heavily obfuscated, the presence of numerous links suggests a social engineering attempt to drive traffic to potentially malicious or misleading content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096095099097097/Doctor-Who-2015-Event-The-Four-Doctors-2-Doctor-Who-2015-Event-Four-Doctors-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/1091091099094094092/Doctor-Doctor-Part-Two-Doctors-Orders-Series-by-Kassandra-Cox.pdf
    • http://loaminoo.linkpc.net/1094097094091096/Doctor-Who-The-Third-Doctor-Volume-1-The-Heralds-of-Destruction-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/8098099093098/Doctor-Who-The-Eight-Doctors-by-Terrance-Dicks.pdf
    • http://loaminoo.linkpc.net/3092090099092095/Doctor-Who-and-the-Three-Doctors-by-Terrance-Dicks.pdf
    • http://loaminoo.linkpc.net/7097099096090/Doctor-Who-Love-and-War-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/2090098098099092/Doctor-Who-Seasons-of-Fear-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/7091098092098094/Doctor-Who-The-Shadows-of-Avalon-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/3093091094094090/Doctor-Who-Human-Nature-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/7099097096099/Doctor-Who-Timewyrm-Revelation-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/3092097099091093/Doctor-Who-Short-Trips-A-Christmas-Treasury-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/4099092096096097/Doctor-Who-The-Tenth-Doctor-Adventures-10th-Doctor-Audio-Originals-by-Peter-Anghelides.pdf
    • http://loaminoo.linkpc.net/1090097096099098099/Computer-Algebra-in-Scientific-Computing-17th-International-Workshop-Casc-2015-Aachen-Germany-September-14-18-2015-Proceedings-by-Vladimir-P-Gerdt.pdf
    • http://loaminoo.linkpc.net/9094093091094098/Football-Outsiders-Almanac-2015-The-Essential-Guide-to-the-2015-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdf
    • http://loaminoo.linkpc.net/6090096095099096/The-Semantic-Web-Latest-Advances-and-New-Domains-12th-European-Semantic-Web-Conference-Eswc-2015-Portoroz-Slovenia-May-31----June-4-2015-Proceedings-by-Fabien-Gandon.pdf
    • http://loaminoo.linkpc.net/6090096095098097/The-Semantic-Web-Latest-Advances-and-New-Domains-12th-European-Semantic-Web-Conference-ESWC-2015-Portoroz-Slovenia-May-31----June-4-2015-Proceedings-Lecture-Notes-in-Computer-Science-by-Fabien-Gandon.pdf
    • http://loaminoo.linkpc.net/1090095099090091090/Reader-s-Digest-2015-Vol-6-Memory-Man-Eight-Hundred-Grapes-Moriarty-Christmas-Light-Reader-s-Digest-Select-Editions-volume-6-2015-by-David-Baldacci.pdf
    • http://loaminoo.linkpc.net/2094096091093094/The-Sockdolager-Fall-2015-Issue-03-by-Paul-Tuttle-Starr.pdf
    • http://loaminoo.linkpc.net/2091091091093098/Doctor-Who-Timeframe-The-Illustrated-History-Doctor-Who-30th-Anniversary-by-David-J-Howe.pdf
    • http://loaminoo.linkpc.net/6093091098096090/Doctor-Who-Time-Reaver-The-Tenth-Doctor-Adventures-1-2-by-Jenny-T-Colgan.pdf