Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6dc5d4751798957…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 20:31:03 +01:00 Authoring application: mPDF 5.7
MD5: 4d605ba9ddb8a3ab793ec34c8b59ab53 SHA-1: f8c49de3a2a2c55ee4d3775e71d11eb6ba3e83a7 SHA-256: f6dc5d4751798957738a4bad0415631151ff90b8fa0d1734b3b6cfbd3f37c972
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the same domain, suggesting a link farm or SEO manipulation tactic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic indicate a malicious intent to redirect users. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093093099095091/The-Twelve-Kingdoms-The-Vast-Spread-of-the-Seas-The-Twelve-Kingdoms-3-by-Fuyumi-Ono.pdf
    • http://loaminoo.linkpc.net/5093095090094/The-Twelve-Kingdoms-Skies-of-Dawn-The-Twelve-Kingdoms-4-by-Fuyumi-Ono.pdf
    • http://loaminoo.linkpc.net/1093099094097098/The-Twelve-Kingdoms-Sea-of-Wind-The-Twelve-Kingdoms-2-by-Fuyumi-Ono.pdf
    • http://loaminoo.linkpc.net/3098092098092094/The-Twelve-Kingdoms-The-Talon-of-the-Hawk-The-Twelve-Kingdoms-3-by-Jeffe-Kennedy.pdf
    • http://loaminoo.linkpc.net/4090090096091099/A-Dance-of-Silver-and-Shadow-A-Retelling-of-The-Twelve-Dancing-Princesses-Beyond-the-Four-Kingdoms-1-by-Melanie-Cellier.pdf
    • http://loaminoo.linkpc.net/3097094093099090/Three-Kingdoms-Volume-01-Heroes-and-Chaos-Three-Kingdoms-1-by-Wei-Dong-Chen.pdf
    • http://loaminoo.linkpc.net/3093098096098/Falling-Kingdoms-Falling-Kingdoms-1-by-Morgan-Rhodes.pdf
    • http://loaminoo.linkpc.net/7090090094094098/Twelve-Hours-Sleep-by-Twelve-Weeks-Old-A-Step-By-Step-Plan-for-Baby-Sleep-Success-by-Suzy-Giordano.pdf
    • http://loaminoo.linkpc.net/6092096095096094/Obscure-Kingdoms-by-Edward-Fox.pdf
    • http://loaminoo.linkpc.net/2096097097099090/Annexed-The-Kingdoms-1-by-Sara-MH.pdf
    • http://loaminoo.linkpc.net/4099096091091092/Romance-of-the-Three-Kingdoms-Set-See-Vol-1-2-by-Luo-Guanzhong.pdf
    • http://loaminoo.linkpc.net/4098091094099091/The-Broken-Kingdoms-by-N-K-Jemisin.pdf
    • http://loaminoo.linkpc.net/6097092093092096/Kingdoms-at-War-Heirs-to-the-Throne-by-J-D-Minard.pdf
    • http://loaminoo.linkpc.net/3098095094091092/You-Bet-Your-Banshee-The-Three-Kingdoms-1-by-Danica-Avet.pdf
    • http://loaminoo.linkpc.net/3096095090099097/Kingdoms-in-Conflict-by-Charles-W-Colson.pdf
    • http://loaminoo.linkpc.net/2095093092096/The-Broken-Kingdoms-Inheritance-2-by-N-K-Jemisin.pdf
    • http://loaminoo.linkpc.net/8093092092098093/The-Bluebird-The-Seven-Kingdoms-9-by-Cordelia-Castel.pdf
    • http://loaminoo.linkpc.net/2092092096090091/Kingdoms-by-Mary-Jane-Salk.pdf
    • http://loaminoo.linkpc.net/2091093098096092/The-Five-Kingdoms-of-Severi-by-Dora-Gonz-lez.pdf
    • http://loaminoo.linkpc.net/2097091090095091/Sky-Bound-Three-Kingdoms-1-by-James-Morris.pdf
    • http://loaminoo.linkpc.net/7090090094094098/Twelve-Hours-Sleep-by-Twelve-Weeks-Old-A-Step-By-S