Malicious PDF — malware analysis report

Static analysis result for SHA-256 f69f0afb2ecacb15…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 20:15:44 +01:00 Authoring application: mPDF 5.7
MD5: 60b1c97c414a45faf22e80fa5e37deb0 SHA-1: 71343b69d94c827404a91063d92d5af2521d5da4 SHA-256: f69f0afb2ecacb15ca55bf11cdded22f3be95c9b0d08cac0066b1ddc1fc81137
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified as a PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096090090095096/Lost-Rights-The-Misadventures-of-a-Stolen-American-Relic-by-David-Howard.pdf
    • http://loaminoo.linkpc.net/2091098092090095/The-Stolen-Relic-Nancy-Drew-Girl-Detective-7-by-Carolyn-Keene.pdf
    • http://loaminoo.linkpc.net/3098094097099091/Misadventures-with-a-Rock-Star-Misadventures-13-by-Helen-Hardt.pdf
    • http://loaminoo.linkpc.net/6099090095/Misadventures-on-the-Night-Shift-Misadventures-5-by-Lauren-Rowe.pdf
    • http://loaminoo.linkpc.net/2096092094090093/NPR-American-Chronicles-Civil-Rights-by-National-Public-Radio.pdf
    • http://loaminoo.linkpc.net/6097093091/Misadventures-of-the-First-Daughter-Misadventures-3-by-Meredith-Wild.pdf
    • http://loaminoo.linkpc.net/9094097094/Misadventures-with-a-Country-Boy-Misadventures-19-by-Elizabeth-Hayley.pdf
    • http://loaminoo.linkpc.net/5098092095094098/American-Flagg-4-by-Howard-Chaykin.pdf
    • http://loaminoo.linkpc.net/3097091093093095/Reporting-Civil-Rights-Part-One-American-Journalism-1941-1963-by-Clayborne-Carson.pdf
    • http://loaminoo.linkpc.net/3098094097099095/Misadventures-of-a-Valedictorian-Misadventures-8-by-M-F-Wild.pdf
    • http://loaminoo.linkpc.net/2093095099097/The-Last-Farmer-An-American-Memoir-by-Howard-Kohn.pdf
    • http://loaminoo.linkpc.net/7097092096091097/Fannie-Never-Flinched-One-Woman-s-Courage-in-the-Struggle-for-American-Labor-Union-Rights-by-Mary-Cronk-Farrell.pdf
    • http://loaminoo.linkpc.net/5098092093094099/American-Flagg-Vol-2-Southern-Comfort-by-Howard-Chaykin.pdf
    • http://loaminoo.linkpc.net/8096099098099/A-People-s-History-of-American-Empire-by-Howard-Zinn.pdf
    • http://loaminoo.linkpc.net/2095090098094097/Johnny-Appleseed-The-Man-the-Myth-the-American-Story-by-Howard-Means.pdf
    • http://loaminoo.linkpc.net/4092092099096095/Stolen-Future-Is-Your-Love-Strong-Enough-Stolen-3-by-Kimberly-Rae.pdf
    • http://loaminoo.linkpc.net/1091092095092092/A-Stolen-Kiss-Stolen-Royals-1-by-Kelsey-Keating.pdf
    • http://loaminoo.linkpc.net/3091094098096097/Stolen-Heat-Stolen-2-by-Elisabeth-Naughton.pdf
    • http://loaminoo.linkpc.net/1095097092090097/Clad-in-Iron-The-American-Civil-War-and-the-Challenge-of-British-Naval-Power-by-Howard-J-Fuller.pdf
    • http://loaminoo.linkpc.net/5095090095094099/Your-Rights-The-Liberty-Guide-to-Human-Rights-by-Farhad-Khosrokhavar.pdf