Malicious PDF — malware analysis report

Static analysis result for SHA-256 e47214792cb314b2…

MALICIOUS

PDF

14.1 KB Created: 2019-05-01 06:10:13 +01:00 Authoring application: mPDF 5.7
MD5: 47b575b03d02e766363eb074b80cc104 SHA-1: b3fb6e2d073d0dbb2cfa0f4a9527f5e6ff095f36 SHA-256: e47214792cb314b2e661b57653bcb66c95a2b4d16dfbf001e7cb16d5e34c7e0d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly indicates this malicious intent. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a high likelihood of malicious activity. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090094093091098/The-Book-of-God-and-Physics-A-Novel-of-the-Voynich-Mystery-by-Enrique-Joven.pdf
    • http://loaminoo.linkpc.net/1091098099094092090/Inscriptions-of-Disputed-Origin-Undeciphered-Writing-Systems-Linear-A-Voynich-Manuscript-Rongorongo-Codex-Seraphinianus-Phaistos-Disc-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/4092098092096095/Enchanters-of-Men-by-Ethel-Mayne.pdf
    • http://loaminoo.linkpc.net/3094099098099093/Seven-Little-Australians-by-Ethel-Turner.pdf
    • http://loaminoo.linkpc.net/3091098090098093/My-Cat-Sammy-by-Ethel-Mannin.pdf
    • http://loaminoo.linkpc.net/5091093095098094/The-Weight-of-Him-by-Ethel-Rohan.pdf
    • http://loaminoo.linkpc.net/4094092093097091/The-Way-of-an-Eagle-by-Ethel-M-Dell.pdf
    • http://loaminoo.linkpc.net/6098097095098/Ann-Of-Ava-by-Ethel-Daniels-Hubbard.pdf
    • http://loaminoo.linkpc.net/4097098093093098/Ethel-s-New-Home-by-Kathy-Rogo.pdf
    • http://loaminoo.linkpc.net/2092093095096099/Seven-Little-Australians-Woolcots-1-by-Ethel-Turner.pdf
    • http://loaminoo.linkpc.net/6090098095092099/Saints-for-the-Journey-by-Ethel-Marbach.pdf
    • http://loaminoo.linkpc.net/2093095099092096/Swamp-Angel-by-Ethel-Wilson.pdf
    • http://loaminoo.linkpc.net/4094091090094092/Ethel-and-Ernest-by-Raymond-Briggs.pdf
    • http://loaminoo.linkpc.net/1099090099096093/Seven-Little-Australians-Woolcots-1-by-Ethel-Turner.pdf
    • http://loaminoo.linkpc.net/8093095099095095/Pasteur-Exposed-by-Ethel-Hume.pdf
    • http://loaminoo.linkpc.net/1090095093091098099/The-Oliphants-of-Gask-by-E-Ethel-Maxtone-Graham.pdf
    • http://loaminoo.linkpc.net/3095091098099094/Love-and-Salt-Water-by-Ethel-Wilson.pdf
    • http://loaminoo.linkpc.net/9097095094094095/Blue-Ethel-by-Jennifer-Black-Reinhardt.pdf
    • http://loaminoo.linkpc.net/1095097093099096/Ethel-A-Love-Story-by-Suzanne-Falkiner.pdf
    • http://loaminoo.linkpc.net/1095090096099094/Julian-Carleton--I-Am-Not-Just-Another-George-by-Ethel-Cook-Wilson.pdf
    • http://loaminoo.linkpc.net/2093095099092096/Swamp-Angel-by-Eth