Malicious PDF — malware analysis report

Static analysis result for SHA-256 fee511791d56d729…

MALICIOUS

PDF

18.0 KB Created: 2019-04-30 04:08:55 +01:00 Authoring application: mPDF 5.7
MD5: 55111741ef1c5b655891f8e2ebd180fb SHA-1: 163cac04de94d4a150cf0ccd9fc8d670bfdb96f6 SHA-256: fee511791d56d72978866d0fc18c4878aac8c8b49cc183bb21f58ea69f5301a3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, also contains these URLs. This suggests the primary purpose is to redirect users to a website that likely hosts more content or potentially malicious files. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093090092096/Godspeed---Die-Reise-beginnt-Across-The-Universe-1-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/1096093098091097/The-Across-the-Universe-Trilogy-Across-the-Universe-1-3-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/4091091091090091/Love-Is-A-Choice-Across-the-Universe-0-6-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/3093096093096/A-Million-Suns-Across-the-Universe-2-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/4093090092095090/Shades-of-Earth-Across-the-Universe-3-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/1090098090097091096/Across-the-Universe-Across-the-Universe-1-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/1090093093092091098/Nur-60-Sekunden-Die-Reise-Beginnt-by-Ann-Klee.pdf
    • http://loaminoo.linkpc.net/3096091098/A-World-Without-You-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/7095095091093093/Despierta-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/5097095097/Rebel-Rising-by-Beth-Revis.pdf
    • http://loaminoo.linkpc.net/1091090098093095098/Wir-sind-dann-mal-woanders---Die-Reise-beginnt-Chile-Erlebnisse-einer-Weltreise-by-Doreen-Goroll.pdf
    • http://loaminoo.linkpc.net/8096092098098098/Gullivers-Reisen-Reise-nach-Lilliput-Reise-nach-Brobdingnag-Reise-nach-Laputa-Reise-in-das-Land-der-Hauyhnhnms---Vollst-ndige-deutsche-Ausgabe-von-Jonathan-Swift-by-Jonathan-Swift.pdf
    • http://loaminoo.linkpc.net/2099090090091/Godspeed-A-Love-Story-by-Dan-Chabot.pdf
    • http://loaminoo.linkpc.net/8090098094096096/Godspeed-Making-Christ-s-Mission-Your-Own-by-Britt-Merrick.pdf
    • http://loaminoo.linkpc.net/2099091090097099/Godspeed-The-Kurt-Cobain-Graphic-by-James-McCarthy.pdf
    • http://loaminoo.linkpc.net/9096093099094092/Ida-Pfeiffer-Ausgew-hlte-Werke-Eine-Frauenfahrt-um-die-Welt-Meine-Zweite-Weltreise-Reise-nach-Madagaskar-Reise-einer-Wienerin-in-das-Heilige-Land-den-Kannibalen-und-mehr-by-Ida-Pfeiffer.pdf
    • http://loaminoo.linkpc.net/1090092092096091091/X-Es-beginnt-by-A-L-Kahnau.pdf
    • http://loaminoo.linkpc.net/2092099094092091/Sapphire-Universe-The-Universe-Series-1-by-Devon-Herrera.pdf
    • http://loaminoo.linkpc.net/1090092092096090098/Bound-to-Suffer---Es-beginnt-by-Jay-El-Nabhan.pdf
    • http://loaminoo.linkpc.net/1090092092096091093/Mord-beginnt-im-Herzen-by-Horst-Bieber.pdf
    • http://loaminoo.linkpc.net/8096092098098098/Gullivers-Reis