Malicious PDF — malware analysis report

Static analysis result for SHA-256 f89f64b67df5a210…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 03:49:57 +01:00 Authoring application: mPDF 5.7
MD5: 90be7cfc612af92ca42be71ff7851f7d SHA-1: d77b567e14027024920d45782c92dc221c9d96b2 SHA-256: f89f64b67df5a210bf4e62e5856027d9066cb6b70cde92f23688598d4c1d9805
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to book titles but are hosted on a dynamic DNS domain, suggesting a potential link farm for SEO manipulation or to distribute further malicious content. While the URLs themselves are marked as benign, the sheer volume and structure of the links within a small PDF file are highly suspicious. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093097092098092/The-Great-Mortality-An-Intimate-History-of-the-Black-Death-the-Most-Devastating-Plague-of-All-Time-by-John-Kelly.pdf
    • http://loaminoo.linkpc.net/1091092095093094/Mao-s-Great-Famine-The-History-Of-China-s-Most-Devastating-Catastrophe-1958-62-by-Frank-Dik-tter.pdf
    • http://loaminoo.linkpc.net/1096099090090095/The-Black-Death-A-Personal-History-by-John-Hatcher.pdf
    • http://loaminoo.linkpc.net/3091099094098098/The-Black-Death-A-Personal-History-by-John-Hatcher.pdf
    • http://loaminoo.linkpc.net/6097093097095/The-Underground-History-of-American-Education-An-Intimate-Investigation-Into-the-Prison-of-Modern-Schooling-by-John-Taylor-Gatto.pdf
    • http://loaminoo.linkpc.net/2090098096097093/The-Graves-Are-Walking-The-Great-Famine-and-the-Saga-of-the-Irish-People-by-John-Kelly.pdf
    • http://loaminoo.linkpc.net/3098093094092096/Plagues-and-Princes-The-Great-Mortality-by-Thomas-Schultz.pdf
    • http://loaminoo.linkpc.net/1095091094099091/The-Great-Death-by-John-E-Smelcer.pdf
    • http://loaminoo.linkpc.net/1091091099094090099/A-History-of-the-Great-War-by-John-Buchan.pdf
    • http://loaminoo.linkpc.net/3096097090092091/A-Brief-History-of-Time-From-the-Big-Bang-to-Black-Holes-by-Stephen-Hawking.pdf
    • http://loaminoo.linkpc.net/6094099095099/A-Brief-History-of-Time-From-the-Big-Bang-to-Black-Holes-by-Stephen-Hawking.pdf
    • http://loaminoo.linkpc.net/3096097093099092/History-Revisited-The-Great-Battles-Eminent-Historians-Take-on-the-Great-Works-of-Alternative-History-by-J-David-Markham.pdf
    • http://loaminoo.linkpc.net/1090096099097090091/Morality-Mortality-Volume-I-Death-and-Whom-to-Save-from-It-Oxford-Ethics-Series-by-F-M-Kamm.pdf
    • http://loaminoo.linkpc.net/2093094090091092/Death-s-Ink-Black-Shadow-More-Heat-Than-the-Sun-6-by-John-Wiltshire.pdf
    • http://loaminoo.linkpc.net/2094099094096090/A-History-of-Ancient-Egypt-From-the-First-Farmers-to-the-Great-Pyramid-by-John-Romer.pdf
    • http://loaminoo.linkpc.net/7098093094099/Under-the-Big-Black-Sun-A-Personal-History-of-L-A-Punk-by-John-Doe.pdf
    • http://loaminoo.linkpc.net/8090097097098095/Black-Mass-Apocalyptic-Religion-and-the-Death-of-Utopia-by-John-N-Gray.pdf
    • http://loaminoo.linkpc.net/1092090092092098/Stalked-by-Death-Touch-of-Death-2-by-Kelly-Hashway.pdf
    • http://loaminoo.linkpc.net/5091095098098099/The-Last-Irish-Plague-The-Great-Flu-Epidemic-in-Ireland-1918-19-by-Caitriona-Foley.pdf
    • http://loaminoo.linkpc.net/2095091090095097/The-Great-Plague-A-London-Girl-s-Diary-1665-1666-by-Pamela-Oldfield.pdf
    • http://loaminoo.linkpc.net/2090098096097093/The-Graves-Are-Walking-The-Great-Fam