Malicious PDF — malware analysis report

Static analysis result for SHA-256 efd7ff0c17259cc9…

MALICIOUS

PDF

21.5 KB Created: 2019-05-03 12:48:53 +01:00 Authoring application: mPDF 5.7
MD5: ffa97f260aaf0d2a196a27ba29c70918 SHA-1: f3d954b893f547d70a6bfe74fca92dd00e24c1f6 SHA-256: efd7ff0c17259cc9f9b75b7c52323818696d460a7b332497320e06e8a7522074
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a heuristic firing for a link farm, indicating an attempt to direct users to numerous external websites. While the document body is heavily obfuscated and unreadable, the presence of 26 external links, many with numeric slugs, suggests a tactic to distribute traffic or potentially host malicious content across multiple domains. The primary attack pattern observed is the use of a link farm to redirect users.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095092093092090/Anyone-You-Want-Me-to-Be-A-True-Story-of-Sex-and-Death-on-the-Internet-by-John-Edward-Douglas.pdf
    • http://loaminoo.linkpc.net/2097099091090099/Inside-the-Mind-of-BTK-The-True-Story-Behind-the-Thirty-Year-Hunt-for-the-Notorious-Wichita-Serial-Killer-by-John-Edward-Douglas.pdf
    • http://loaminoo.linkpc.net/2097099097096094/Burke-amp-Hare-The-True-Story-Story-of-the-Bodysnatchers-by-Hugh-Douglas.pdf
    • http://loaminoo.linkpc.net/2097099090092099/Obsession-by-John-Edward-Douglas.pdf
    • http://loaminoo.linkpc.net/5099094091096/Journey-Into-Darkness-Mindhunter-2-by-John-Edward-Douglas.pdf
    • http://loaminoo.linkpc.net/3091099090090096/Mousetronaut-Based-on-a-Partially-True-Story-by-Mark-Edward-Kelly.pdf
    • http://loaminoo.linkpc.net/3093098092096092/The-Nuclear-Jihadist-The-True-Story-of-the-Man-Who-Sold-the-World-s-Most-Dangerous-Secrets-and-How-We-Could-Have-Stopped-Him-by-Douglas-Frantz.pdf
    • http://loaminoo.linkpc.net/4093097091093092/To-Die-A-Dry-Death-The-True-Story-of-the-Batavia-Shipwreck-by-Greta-van-der-Rol.pdf
    • http://loaminoo.linkpc.net/8092091091096098/The-Beauty-of-Wings-A-True-Story-of-Transformation-from-Near-Death-to-Unconditional-Love-by-Alexandra-Mika.pdf
    • http://loaminoo.linkpc.net/1091093093094095/Sin-Bin-The-Untold-Story-Of-A-True-Footy-Bad-Boy-by-John-Elias.pdf
    • http://loaminoo.linkpc.net/2096093093091094/The-Obedient-Assassin-A-Novel-Based-on-a-True-Story-by-John-P-Davidson.pdf
    • http://loaminoo.linkpc.net/4099090098095/When-The-Dust-Settles---A-True-Hollywood-Story-by-John-A-Andrews.pdf
    • http://loaminoo.linkpc.net/3095091091094090/The-Tiger-A-True-Story-Of-Vengeance-And-Survival-by-John-Vaillant.pdf
    • http://loaminoo.linkpc.net/1098095093099091/At-the-Mercy-of-the-Sea-The-True-Story-of-Three-Sailors-in-a-Caribbean-Hurricane-by-John-Kretschmer.pdf
    • http://loaminoo.linkpc.net/4094096091095090/The-Colony-The-Harrowing-True-Story-of-the-Exiles-of-Molokai-by-John-Tayman.pdf
    • http://loaminoo.linkpc.net/5092096092096095/Six-Miles-to-Charleston-The-True-Story-of-John-and-Lavinia-Fisher-by-Bruce-Orr.pdf
    • http://loaminoo.linkpc.net/1091094094095096093/Challenges-and-Love-The-True-Story-of-John-Nemec-by-John-Nemec.pdf
    • http://loaminoo.linkpc.net/6096092097090097/The-Politics-of-Micro-Decisions-Edward-Snowden-Net-Neutrality-and-the-Architectures-of-the-Internet-by-Florian-Sprenger.pdf
    • http://loaminoo.linkpc.net/2093099094097093/The-Dancing-Plague-The-Strange-True-Story-of-an-Extraordinary-Illness-by-John-Waller.pdf
    • http://loaminoo.linkpc.net/5094093096099/Argall-The-True-Story-of-Pocahontas-and-Captain-John-Smith-by-William-T-Vollmann.pdf
    • http://loaminoo.linkpc.net/2097099097096094/Burke-amp-Hare-The-True-Story-Story-of-t