Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed519b1bb170e2c3…

MALICIOUS

PDF

17.0 KB Created: 2019-05-02 17:44:16 +01:00 Authoring application: mPDF 5.7
MD5: 65163a5f4fa7a731bd2b42ed14ad4055 SHA-1: 55fca7c8d38ccabdfb6da139ba8869d7a53933d8 SHA-256: ed519b1bb170e2c361780053f9cc07120499285f4b13e90e85eda65079cdc57e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of external links, forming a link farm. The primary heuristic indicates a PDF_SEO_LINK_FARM, suggesting the document's purpose is to drive traffic to these external URLs. While the URLs themselves are currently marked as benign, the sheer volume and structure point towards a malicious intent, likely to host malicious content or engage in SEO manipulation for malicious purposes. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099092090098091/Van-Eyck-The-Complete-Works-by-Till-Holger-Borchert.pdf
    • http://loaminoo.linkpc.net/9099091098092094/The-Age-of-Van-Eyck-The-Mediterranean-World-and-Early-Netherlandish-Painting-1430-1530-by-Till-Holger-Borchert.pdf
    • http://loaminoo.linkpc.net/9099091097097096/The-Life-and-Works-of-Wolfgang-Borchert-by-Burgess-Gordon-J-a.pdf
    • http://loaminoo.linkpc.net/9099091099096093/Unpublishable-Works-Wolfgang-Borchert-s-Literary-Production-in-Nazi-Germany-by-Erwin-J-Warkentin.pdf
    • http://loaminoo.linkpc.net/9099091098093094/Wolfgang-Borchert-Wer-gibt-Antwort-Wolfgang-Borchert-sein-Werk-und-seine-Wirkung-by-Karl-Sch-n.pdf
    • http://loaminoo.linkpc.net/2092092091090096/Complete-Works-by-Baruch-Spinoza.pdf
    • http://loaminoo.linkpc.net/1099090094099091/The-Complete-Works-of-Chuang-Tzu-by-Zhuangzi.pdf
    • http://loaminoo.linkpc.net/3095096098090/Complete-Works-by-Arthur-Rimbaud.pdf
    • http://loaminoo.linkpc.net/8097097092097/The-Complete-Works-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/3092093093094/The-Complete-Works-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1099098090091092/Complete-Works-One-by-Harold-Pinter.pdf
    • http://loaminoo.linkpc.net/8099096093094092/Caravaggio-The-Complete-Works-by-Sebastian-Sch-tze.pdf
    • http://loaminoo.linkpc.net/4099091092097/Maldoror-and-the-Complete-Works-by-Comte-de-Lautr-amont.pdf
    • http://loaminoo.linkpc.net/8099096095097099/Caravaggio-The-Complete-Works-by-Rossella-Vodret.pdf
    • http://loaminoo.linkpc.net/4097094095099097/The-Complete-Mystical-Works-by-Meister-Eckhart.pdf
    • http://loaminoo.linkpc.net/1091097099093092097/The-Complete-E-M-Forster-Collection-11-Complete-Works-by-E-M-Forster.pdf
    • http://loaminoo.linkpc.net/9099094092093094/The-Complete-Works-of-Marvin-K-Mooney-by-Christopher-Higgs.pdf
    • http://loaminoo.linkpc.net/3098098091099096/Mega-Man-X-Official-Complete-Works-by-Udon-Entertainment.pdf
    • http://loaminoo.linkpc.net/1090092097091097090/Complete-and-Systematic-Concordance-of-Works-of-Shakespeare-by-Marvin-Spevack.pdf
    • http://loaminoo.linkpc.net/1090099092091094091/Adrian-Frutiger---Typefaces-The-Complete-Works-by-Heidrun-Osterer.pdf
    • http://loaminoo.linkpc.net/1099090094099091/The-Complete-W