Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2862940f875fb75…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 01:13:45 +01:00 Authoring application: mPDF 5.7
MD5: 556c0e790441d5fa8cf2781df43db3fe SHA-1: 20588b15b0c94b9b5d105007f358893d4e8c778e SHA-256: f2862940f875fb750a69f0cb816073784512b274000d23d6b9a23fad942e3039
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that this is a technique to artificially inflate search engine rankings or to distribute a large volume of content. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to direct users to potentially harmful or deceptive content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097091098097093/Scripture-Alone-The-Evangelical-Doctrine-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/2095092090098098/The-Bible-Made-Impossible-Why-Biblicism-Is-Not-a-Truly-Evangelical-Reading-of-Scripture-by-Christian-Smith.pdf
    • http://loaminoo.linkpc.net/1091097094094091097/Evangelical-pioneers-in-Ethiopia-origins-of-the-Evangelical-church-Mekane-Yesus-by-Gustav-Aren.pdf
    • http://loaminoo.linkpc.net/8094095099098095/Doctrine-for-a-Smaller-Air-Force-Mali-and-the-Question-of-Unique-Air-Doctrine-by-Sory-Ibrahim-Kone.pdf
    • http://loaminoo.linkpc.net/4091093092096/The-Holiness-of-God-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/5098093098094095/Matthew-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/5098093098094093/Mark-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/1090091099099095/Johnny-Come-Home-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/1094092090095098/The-Prayer-of-the-Lord-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/3091093093097093/The-Prince-s-Poison-Cup-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/1093098097096093/The-Last-Days-According-to-Jesus-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/5094099091090096/Who-Is-Jesus-Crucial-Questions-1-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/2095097098092095/Bound-for-Glory-God-s-Promise-for-Your-Family-by-R-C-Sproul-Jr-.pdf
    • http://loaminoo.linkpc.net/7096094099095091/Surprised-by-Suffering-The-Role-of-Pain-and-Death-in-The-Christian-Life-by-R-C-Sproul.pdf
    • http://loaminoo.linkpc.net/1090091099099096/Evangelical-Dictionary-of-Theology-by-Walter-A-Elwell.pdf
    • http://loaminoo.linkpc.net/1091097094099098094/History-of-the-Evangelical-Church-by-Samuel-P-Spreng.pdf
    • http://loaminoo.linkpc.net/1098097091095091/Believers-A-Journey-Into-Evangelical-America-by-Jeffery-L-Sheler.pdf
    • http://loaminoo.linkpc.net/8091094090096090/Fiel-Distinctives-of-the-Evangelical-Church-in-Spain-by-E-J-Barto.pdf
    • http://loaminoo.linkpc.net/3096095092099096/The-Real-Scandal-of-the-Evangelical-Mind-by-Carl-R-Trueman.pdf
    • http://loaminoo.linkpc.net/3096096098095094/When-God-Talks-Back-Understanding-the-American-Evangelical-Relationship-with-God-by-T-M-Luhrmann.pdf
    • http://loaminoo.linkpc.net/5098093098094095/Matthew-