Malicious PDF — malware analysis report

Static analysis result for SHA-256 23dd0c16e805727d…

MALICIOUS

PDF

19.1 KB Created: 2019-04-30 02:11:24 +01:00 Authoring application: mPDF 5.7
MD5: ff406fd05b0ba9d806dd9e860c319a5d SHA-1: 17fcd60f0ef25e734e0cd0dbe23961f32ddab80e SHA-256: 23dd0c16e805727dca5364ad606ab6555798ce854947fa27a5eabea98a81941a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact user-facing lure. The primary attack pattern observed is the mass distribution of links to external resources.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201206209208200/Shadows-of-the-Night-Queer-Tales-of-the-Uncanny-and-Unusual-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/2207209203208202/Florida-Happens-Tales-of-Mystery-Mayhem-and-Suspense-from-the-Sunshine-State-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/9202209200202209/Wanna-Wrestle-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/4205204209209201/Who-Dat-Whodunnit-Scotty-Bradley-5-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/4205204208208201/Murder-In-The-Rue-St-Ann-Chanse-MacLeod-2-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/4205205204201209/Murder-in-the-Arts-District-Chanse-MacLeod-7-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/3200202208201206/Jackson-Square-Jazz-Scotty-Bradley-2-by-Greg-Herren.pdf
    • http://xiixmcuin.linkpc.net/3200207207208201/Gaslight-Arcanum-Uncanny-Tales-of-Sherlock-Holmes-by-J-R-Campbell.pdf
    • http://xiixmcuin.linkpc.net/1205206201208203/Mad-Shadows-The-Weird-Tales-of-Dorgo-the-Dowser-Mad-Shadows-1-by-Joe-Bonadonna.pdf
    • http://xiixmcuin.linkpc.net/1209200204208/Portland-Queer-Tales-of-the-Rose-City-by-Ariel-Gore.pdf
    • http://xiixmcuin.linkpc.net/1208207204202200/Night-Shield-amp-Night-Moves-Night-Tales-5-amp-6-by-Nora-Roberts.pdf
    • http://xiixmcuin.linkpc.net/3200203202206201/A-Treasury-of-Civil-War-Tales-Unusual-Interesting-Stories-of-the-Turbulent-Era-When-Americans-Waged-War-on-Americans-by-Webb-Garrison.pdf
    • http://xiixmcuin.linkpc.net/4201207204202206/BRAN-MAK-MORN---The-Last-King-Men-of-the-Shadows-Kings-of-the-Night-A-Song-of-the-Race-Worms-of-the-Earth-The-Dark-Man-The-Lost-Race-The-Little-People-The-Children-of-the-Night-by-Robert-E-Howard.pdf
    • http://xiixmcuin.linkpc.net/1208206201206207/Nightshade-Night-Smoke-Night-Tales-3-4-by-Nora-Roberts.pdf
    • http://xiixmcuin.linkpc.net/1208207204201209/Night-Tales-Nightshade-amp-Night-Smoke-by-Nora-Roberts.pdf
    • http://xiixmcuin.linkpc.net/3200201201203201/Night-Smoke-Night-Tales-4-by-Nora-Roberts.pdf
    • http://xiixmcuin.linkpc.net/2201206204201200/Night-Shield-Night-Tales-5-by-Nora-Roberts.pdf
    • http://xiixmcuin.linkpc.net/7206200201203200/Bookshop-And-Other-Tales-of-Terror-by-Greg-Kaczynski.pdf
    • http://xiixmcuin.linkpc.net/3204202203200207/The-End-of-Halloween-Four-Tales-of-All-Hallows-Eve-by-Greg-Chapman.pdf
    • http://xiixmcuin.linkpc.net/9203201200205206/Rigorous-Mortis-A-Mortician-s-Tales-by-Greg-McWhorter.pdf