Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcd8baba3c9c9235…

MALICIOUS

PDF

25.3 KB Created: 2019-04-30 20:30:41 +01:00 Authoring application: mPDF 5.7
MD5: 920a7a1ffaf398dcd7d697bd5b632f30 SHA-1: ed9dee457e71c42131fda163349bfd4272ed871b SHA-256: fcd8baba3c9c9235643613938064e23aea18d3ebe8e5e2d618fe8744472a7874
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified as a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that the PDF is designed to direct users to numerous external PDF documents. While the document body is heavily obfuscated, the presence of many links suggests a social engineering tactic to drive traffic to potentially malicious or unwanted content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099091097098092/Sweat-A-Practical-Plan-for-Keeping-Your-Heart-Intact-While-Loving-an-Addict-by-Denise-Krochta.pdf
    • http://loaminoo.linkpc.net/2099095090095099/Loving-Her-Keeping-Her-2-by-Kelly-Lucille.pdf
    • http://loaminoo.linkpc.net/2099090094093099/Loving-Pedro-Infante-A-Novel-by-Denise-Ch-vez.pdf
    • http://loaminoo.linkpc.net/6092090094093093/Loving-Someone-with-PTSD-A-Practical-Guide-to-Understanding-and-Connecting-with-Your-Partner-after-Trauma-by-Aphrodite-Matsakis.pdf
    • http://loaminoo.linkpc.net/6090094090094097/The-Business-Plan-Workbook-A-Practical-Guide-to-New-Venture-Creation-and-Development-by-Colin-Barrow.pdf
    • http://loaminoo.linkpc.net/8097094090090096/Unifying-Truths-of-the-World-s-Religions-Practical-Principles-for-Living-and-Loving-in-Peace-by-C-David-Lundberg.pdf
    • http://loaminoo.linkpc.net/1096095092093090/Rude-Awakenings-of-a-Jane-Austen-Addict-Jane-Austen-Addict-2-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/1090098091097091097/Practical-Remarks-Upon-the-Education-of-the-Working-Classes-With-an-Account-of-the-Plan-Pursued-Under-the-Superintendence-of-the-Children-s-Friend-Society-at-the-Brenton-Asylum-Hackney-Wick-by-Charles-Forss.pdf
    • http://loaminoo.linkpc.net/8096094099093/Confessions-of-a-Jane-Austen-Addict-Jane-Austen-Addict-1-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/4091091097096093/The-Owner-of-His-Heart-50-Loving-States-1-by-Theodora-Taylor.pdf
    • http://loaminoo.linkpc.net/2094099092097098/The-Contingency-Plan-The-Lonely-Heart-4-by-Latrivia-S-Nelson.pdf
    • http://loaminoo.linkpc.net/1096099099095091/The-Owner-of-His-Heart-50-Loving-States-Pennsylvania-by-Theodora-Taylor.pdf
    • http://loaminoo.linkpc.net/4097099097091097/Heart-Sparks-7-Practices-For-Loving-Your-Life-by-Ruth-Davis.pdf
    • http://loaminoo.linkpc.net/2092090091099096/Loving-Conor-A-Clairvoyant-s-Memoir-on-Loving-Bonding-and-Healing-by-Tami-Arlene-Urbanek.pdf
    • http://loaminoo.linkpc.net/1094093092091095/The-Jesus-Creed-Loving-God-Loving-Others-by-Scot-McKnight.pdf
    • http://loaminoo.linkpc.net/8099090093094099/Keto-Diet-Plan-Quick-and-Easy-Ketogenic-Meal-Plan-by-Natalie-Kordon.pdf
    • http://loaminoo.linkpc.net/7090098098092097/A-Plan-of-Mr-Pope-s-Garden-As-It-Was-Left-at-His-Death-With-a-Plan-and-Perspective-View-of-the-Grotto-by-John-Serle.pdf
    • http://loaminoo.linkpc.net/4099097098091099/Running-Lean-Iterate-from-Plan-A-to-a-Plan-That-Works-by-Ash-Maurya.pdf
    • http://loaminoo.linkpc.net/1091097098090096097/Practical-Guide-To-Teaching-English-Within-The-National-Curriculum-Practical-Guides-Series-by-Bill-Laar.pdf
    • http://loaminoo.linkpc.net/1090096093091093091/Vom-Vampir-gefickt-und-gebissen-Non-Human-NonHuman-Geschichten-von-Denise-Lagarde-German-Edition-by-Denise-Lagarde.pdf
    • http://loaminoo.linkpc.net/6090094090094