Malicious PDF — malware analysis report

Static analysis result for SHA-256 1eea61dfe0f488d1…

MALICIOUS

PDF

12.7 KB Created: 2019-04-30 09:05:26 +01:00 Authoring application: mPDF 5.7
MD5: 8467b9713675eccac6b78604602e53a0 SHA-1: 07e4b3749b082fdfb1ac3ddf736d2133c985992f SHA-256: 1eea61dfe0f488d1bf590baf311ba65d50e141adb146f10b3a4fd6a9057e0388
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to book titles hosted on the `xiixmcuin.linkpc.net` domain. This heuristic firing indicates a link farm, often used for SEO poisoning or to distribute malicious content. While the URLs themselves are marked as benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent to drive traffic or potentially serve further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2201205207205205/Fingersmith-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/2207206206208/The-Little-Stranger-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/1209201201205/Fingersmith-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/3207208200203207/The-Little-Stranger-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/4202209208209207/Affinity-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/5202204201200207/Derri-re-la-porte-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/1207206206207203/Tipping-the-Velvet-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/7205203202205/Tipping-the-Velvet-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/9203207201207209/Fremde-G-ste-Roman-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/3200202208209203/Dancing-with-Mr-Darcy-Stories-inspired-by-Jane-Austen-and-Chawton-House-by-Sarah-Waters.pdf
    • http://xiixmcuin.linkpc.net/1209202209204208/Paying-The-Piper-by-D-J-Bennett.pdf
    • http://xiixmcuin.linkpc.net/5207201205203204/Constant-Guests-by-Patricia-Nedelea.pdf
    • http://xiixmcuin.linkpc.net/6209205206208/The-Uninvited-Guests-by-Sadie-Jones.pdf
    • http://xiixmcuin.linkpc.net/4209204202203202/The-Uninvited-Guests-by-Sadie-Jones.pdf
    • http://xiixmcuin.linkpc.net/5204204209202207/Paying-the-Piper-by-David-Drake.pdf
    • http://xiixmcuin.linkpc.net/4204203203209204/Guests-of-the-Nation-by-Frank-O-39-Connor.pdf
    • http://xiixmcuin.linkpc.net/1201201201203204206/Apathy-and-Paying-Rent-by-Zach-VandeZande.pdf
    • http://xiixmcuin.linkpc.net/1201208207206206205/Paying-for-Productivity-A-Look-at-the-Evidence-by-Alan-S-Blinder.pdf
    • http://xiixmcuin.linkpc.net/2201200207201207/Paying-The-Debt-Innocence-Claimed-3-by-Madison-Faye.pdf
    • http://xiixmcuin.linkpc.net/1208207201207208/Buzz-A-Year-of-Paying-Attention-by-Katherine-Ellison.pdf
    • http://xiixmcuin.linkpc.net/42