Malicious PDF — malware analysis report

Static analysis result for SHA-256 e47b5abd732dc6f9…

MALICIOUS

PDF

18.9 KB Created: 2019-05-04 14:37:09 +01:00 Authoring application: mPDF 5.7
MD5: 5427845f28a61b8adece54befa4b576b SHA-1: 80f492bcf39e183a76b96544c5caa8a34cf2221b SHA-256: e47b5abd732dc6f9b9d8320b692ebd2003e412d9edb0d3d4a0a67429a9be2f02
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, constituting a link farm. The primary heuristic indicates this is a critical finding, suggesting a malicious intent to direct users to potentially harmful content. No scripts were extracted, and the document body primarily consists of these links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097094093094090/Random-Acts-of-Fantasy-Random-3-Invitation-to-Eden-2-by-Julia-Kent.pdf
    • http://loaminoo.linkpc.net/2097092099096096/Random-Acts-of-Kindness-by-Danny-Wallace.pdf
    • http://loaminoo.linkpc.net/2094093093095091/Random-Acts-Of-Heroic-Love-by-Danny-Scheinmann.pdf
    • http://loaminoo.linkpc.net/3095096093095099/Random-Acts-of-Blindness-An-Erotic-Novel-by-Kelli-Jae-Baeli.pdf
    • http://loaminoo.linkpc.net/7096094090099092/My-Random-Acts-of-Kindness-Journal-by-Tasha-Deschambault.pdf
    • http://loaminoo.linkpc.net/7093099091095097/Random-Acts-Joanna-Brady-16-6-Ali-Reynolds-11-5-by-J-A-Jance.pdf
    • http://loaminoo.linkpc.net/1095095098097091/Ambient-by-Jack-Womack.pdf
    • http://loaminoo.linkpc.net/3094097090094090/Random-Acts-of-Travel-Featuring-Trepidation-Hammocks-and-Spitting-by-Dean-Johnston.pdf
    • http://loaminoo.linkpc.net/1090097092096094096/20-Years-Later-A-Celebration-Of-Life-A-Pay-it-Forward-Random-Acts-of-Kindness-Story-by-Scott-Schluter.pdf
    • http://loaminoo.linkpc.net/5094091091091/Acts-of-Violence-by-Ryan-David-Jahn.pdf
    • http://loaminoo.linkpc.net/3091093092097093/The-Random-House-Book-of-Poetry-for-Children-by-Jack-Prelutsky.pdf
    • http://loaminoo.linkpc.net/3094097095094091/Senseless-2-Senseless-2-by-Kol-Anderson.pdf
    • http://loaminoo.linkpc.net/4099094092098099/Jack-Straw-A-Farce-in-Three-Acts-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/3097090097092099/Boston-Riots-Three-Centuries-of-Social-Violence-by-Jack-Tager.pdf
    • http://loaminoo.linkpc.net/5095094096093096/Meditations-on-Violence-A-Comparison-of-Martial-Arts-Training-amp-Real-World-Violence-by-Rory-Miller.pdf
    • http://loaminoo.linkpc.net/7097099096095/Random-Passage-Random-Passage-1-by-Bernice-Morgan.pdf
    • http://loaminoo.linkpc.net/1091096091099096095/Random-House-Dictionary-of-Abbreviations-by-Random-House.pdf
    • http://loaminoo.linkpc.net/1091097097095092097/Circumcision-excision-racism-sexism-and-violence-The-greatest-crime-against-humanity-an-artificial-racism-masked-behind-tradition-religion-culture-and-folklore-catalyst-of-violence-by-Michel-Herve-Bertaux-Navoiseau.pdf
    • http://loaminoo.linkpc.net/2091092093098095/Senseless-by-Stona-Fitch.pdf
    • http://loaminoo.linkpc.net/5090091097097/Empire-of-the-Senseless-by-Kathy-Acker.pdf
    • http://loaminoo.linkpc.net/3091093092097093/The-Random-House-Book-of-Poetry-for-Chil