Malicious PDF — malware analysis report

Static analysis result for SHA-256 255b386b76d9c38b…

MALICIOUS

PDF

19.5 KB Created: 2019-05-04 14:00:42 +01:00 Authoring application: mPDF 5.7
MD5: 8ea590bf7ed43f27c0093c7279e56294 SHA-1: 701fb9b73047ebe6e9e137495aa614118a60b65f SHA-256: 255b386b76d9c38baa755b2a4a0f657fe472b7377df5fe0424c3abc6085160b4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on a dynamic DNS domain, suggesting a link farm or a method to distribute potentially malicious content under the guise of legitimate resources. No scripts were extracted from this sample. The primary attack pattern involves directing users to a large number of external URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.link
    • http://xiixmcuin.linkpc.net/6205200207206204/American-Aristocrats-A-Family-a-Fortune-and-the-Making-of-American-Capitalism-by-Harry-S-Stout.pdf
    • http://xiixmcuin.linkpc.net/5200208203206202/The-Making-of-Global-Capitalism-The-Political-Economy-Of-American-Empire-by-Leo-Panitch.pdf
    • http://xiixmcuin.linkpc.net/2204208202207207/The-Half-Has-Never-Been-Told-Slavery-and-the-Making-of-American-Capitalism-by-Edward-E-Baptist.pdf
    • http://xiixmcuin.linkpc.net/3200205209200203/The-Best-American-Sports-Writing-2018-by-Glenn-Stout.pdf
    • http://xiixmcuin.linkpc.net/4204201209203205/Country-Soul-Making-Music-and-Making-Race-in-the-American-South-by-Charles-L-Hughes.pdf
    • http://xiixmcuin.linkpc.net/3206209205207206/American-Colossus-The-Triumph-of-Capitalism-1865-1900-by-H-W-Brands.pdf
    • http://xiixmcuin.linkpc.net/9203207204203202/American-Colossus-The-Triumph-of-Capitalism-1865-1900-by-H-W-Brands.pdf
    • http://xiixmcuin.linkpc.net/5201204202207206/So-Great-a-Proffit-How-the-East-Indies-Trade-Transformed-Anglo-American-Capitalism-by-James-R-Fichter.pdf
    • http://xiixmcuin.linkpc.net/1209202201206205/Bad-Money-Reckless-Finance-Failed-Politics-and-the-Global-Crisis-of-American-Capitalism-by-Kevin-Phillips.pdf
    • http://xiixmcuin.linkpc.net/1208209202203205/American-Dynasty-Aristocracy-Fortune-and-the-Politics-of-Deceit-in-the-House-of-Bush-by-Kevin-Phillips.pdf
    • http://xiixmcuin.linkpc.net/3206206206206208/American-Front-The-Great-War-1-by-Harry-Turtledove.pdf
    • http://xiixmcuin.linkpc.net/3206206206207208/Blood-amp-Iron-American-Empire-1-by-Harry-Turtledove.pdf
    • http://xiixmcuin.linkpc.net/3206206209200202/The-Center-Cannot-Hold-American-Empire-2-by-Harry-Turtledove.pdf
    • http://xiixmcuin.linkpc.net/2201203208204/The-Gulf-The-Making-of-An-American-Sea-by-Jack-E-Davis.pdf
    • http://xiixmcuin.linkpc.net/1201209205204205201/Yaddo-Making-American-Culture-by-Micki-McGee.pdf
    • http://xiixmcuin.linkpc.net/4207207204203206/Between-Worlds-The-Making-of-an-American-Life-by-Bill-Richardson.pdf
    • http://xiixmcuin.linkpc.net/1202200200205200/The-American-Dream-HisStory-in-the-Making-by-David-Lee-Windecher.pdf
    • http://xiixmcuin.linkpc.net/1202204205205200/The-Amazing-Harry-Kellar-Great-American-Magician-by-Gail-Jarrow.pdf
    • http://xiixmcuin.linkpc.net/5200209200201/Black-Fire-The-Making-of-an-American-Revolutionary-by-Nelson-Peery.pdf
    • http://xiixmcuin.linkpc.net/1207202209203206/Moral-Minorities-and-the-Making-of-American-Democracy-by-Kyle-G-Volk.pdf