Malicious PDF — malware analysis report

Static analysis result for SHA-256 3802628b3a4cdc5d…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 02:37:22 +01:00 Authoring application: mPDF 5.7
MD5: 6e654a88b6a55adb6801d1234f641383 SHA-1: 91020b3b28a7348c92c20475090edd10a537dd07 SHA-256: 3802628b3a4cdc5d38f2f9b34911d10f3caf465595e60016b89e799b90f56140
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body consists solely of these URLs, suggesting a link farm or redirection tactic. No scripts were extracted from this sample. The primary attack pattern involves directing users to a multitude of external sites.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8209204203205205/Die-Wurst-by-Rainer-Nemayer.pdf
    • http://xiixmcuin.linkpc.net/1200204208201203205/EISKALTE-JAGD---Eine-Gangsterjagd-im-Schneesturm-Ein-Kinderkrimi-auf-Usedom-von-Hans-Rainer-Riekers-by-Hans-Rainer-Riekers.pdf
    • http://xiixmcuin.linkpc.net/9207201200203206/Rainer-Brunn-3-Walzer-Fr-Gitarre-by-Rainer-Brunn.pdf
    • http://xiixmcuin.linkpc.net/8209204204209204/Es-ist-mir-Wurst-by-Bernie-Martin.pdf
    • http://xiixmcuin.linkpc.net/1208200208207201/No-Wurst-For-Were-by-Sir-Wilhelm-Lexicon-Withershins-I-I-I.pdf
    • http://xiixmcuin.linkpc.net/8209204206200207/Das-deutsche-Wurst--und-Fleischerhandwerk-by-August-Ashauer.pdf
    • http://xiixmcuin.linkpc.net/8209204202209203/The-Wurst-of-Grimtooth-s-Traps-by-Rick-Loomis.pdf
    • http://xiixmcuin.linkpc.net/8209204205204207/Der-Hans-Wurst-Streit-in-Wien-by-Karl-Von-Gorner.pdf
    • http://xiixmcuin.linkpc.net/9206203206205204/Wofur-Lohnt-Es-Sich-Zu-Leben-by-Franz-Wurst.pdf
    • http://xiixmcuin.linkpc.net/8209204202208206/Deadly-Sixteen-The-Spirit-Walker-Book-1-by-Duane-Wurst.pdf
    • http://xiixmcuin.linkpc.net/9204203203202203/Translations-from-the-Poetry-of-Rainer-Maria-Rilke-by-Rainer-Maria-Rilke.pdf
    • http://xiixmcuin.linkpc.net/8209204206200209/Wurst-Case-Scenario-Courtney-Von-Dragen-Smith-2-by-Catherine-Clark.pdf
    • http://xiixmcuin.linkpc.net/8209204206201206/Able-How-One-Company-s-Disabled-Workforce-Became-The-Key-To-Extraordinary-Success-by-Nancy-Henderson-Wurst.pdf
    • http://xiixmcuin.linkpc.net/7201206209202203/The-Films-of-Yvonne-Rainer-by-Yvonne-Rainer.pdf
    • http://xiixmcuin.linkpc.net/8208200201206201/Tolle-Wurst-Viel-Spa-beim-Kaviar-Naschen-by-Ragnar-Hillsum.pdf
    • http://xiixmcuin.linkpc.net/8209204205204200/Descending-from-the-Clouds-A-Memoir-of-Combat-in-the-505-Parachute-Infantry-Regiment-82d-Airborne-Division-by-Spencer-F-Wurst.pdf
    • http://xiixmcuin.linkpc.net/9204203204201200/Werke-von-Rainer-Maria-Rilke-by-Rainer-Maria-Rilke.pdf
    • http://xiixmcuin.linkpc.net/8206204205209203/Wasser-statt-Wurst-Br-he-statt-Bier-Heilfasten---Ein-Selbstversuch-by-Thomas-Dix.pdf
    • http://xiixmcuin.linkpc.net/8209204205204201/Hurst-s-Wurst-Colonel-Fielding-Hurst-and-the-Sixth-Tennessee-Cavalry-U-S-A-by-Kevin-D-McCann.pdf
    • http://xiixmcuin.linkpc.net/8209204202208208/Ich-Conchita-Meine-Geschichte-We-are-unstoppable-by-Conchita-Wurst.pdf
    • http://xiixmcuin.linkpc.net/9204203203202203/Translations-from-the-Poetry-of-Rainer-Maria-Rilke-by-R