Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2992df987d02d30…

MALICIOUS

PDF

14.9 KB Created: 2019-05-02 18:29:41 +01:00 Authoring application: mPDF 5.7
MD5: 51f8783a427309983ad862a01817af9b SHA-1: 1bc0dc21538ab5b8c8dd90c722ccef5e72f2c79b SHA-256: f2992df987d02d30defc61f92923a5fa45a3a423d31fec793511aea697993837
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs that point to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly indicates this malicious intent. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a high likelihood of malicious activity. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096090096093091/A-Work-of-Beauty-Alexander-McCall-Smith-s-Edinburgh-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093091095094092/One-City-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7090094090092092/Les-larmes-de-la-girafe-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7099097091091092/Amori-in-viaggio-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/9096094092099099/T-r-an-T-r-in-der-44-Scotland-Street-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093094097096098/Tears-of-the-Giraffe-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/6098090098097090/Akimbo-and-the-Elephants-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4091096096099093/The-House-of-Unexpected-Sisters-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4098099099095096/Blue-Shoes-and-Happiness-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/2091097094099090/The-Dog-who-Came-in-from-the-Cold-Corduroy-Mansions-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3099090098096095/Morality-For-Beautiful-Girls-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1098096098098099/La-s-Orchestra-Saves-the-World-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4090098096095098/The-Dog-who-came-in-from-the-Cold-Corduroy-Mansions-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4098099097093096/Morality-for-Beautiful-Girls-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093091093095097/Espresso-Tales-44-Scotland-Street-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3096091098098098/The-Bertie-Project-44-Scotland-Street-11-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1096097098095096/The-Careful-Use-of-Compliments-Isabel-Dalhousie-4-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3096096094090093/The-Right-Attitude-to-Rain-Isabel-Dalhousie-3-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4096095099091092/A-Distant-View-of-Everything-Isabel-Dalhousie-11-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/4090098093097099/Precious-and-Grace-No-1-Ladies-Detective-Agency-17-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1098096098098099/La-s-Orchestra-Saves-t