Malicious PDF — malware analysis report

Static analysis result for SHA-256 39a3e398b73024b6…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 05:57:32 +01:00 Authoring application: mPDF 5.7
MD5: 3addce5a3ba301e0a84e8a4ef4bbd856 SHA-1: b38a04c0ae1dad2cc856565be602705b5ff71438 SHA-256: 39a3e398b73024b6364cf61be1398c72e2d0e16da931dda148f632eae03891e3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking academic papers, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6204201202209202/Many-Shades-of-Red-State-Policy-and-Collective-Agriculture-by-Mieke-Meurs.pdf
    • http://xiixmcuin.linkpc.net/8203204207203203/Business-the-State-and-Economic-Policy-by-Grant-G-Amyot.pdf
    • http://xiixmcuin.linkpc.net/4209205205206208/Strong-Society-Smart-State-The-Rise-of-Public-Opinion-in-China-s-Japan-Policy-by-James-Reilly.pdf
    • http://xiixmcuin.linkpc.net/1201204202207204209/Directive-Principles-of-State-Policy-in-Der-Indischen-Verfassung-Unter-Berucksichtigung-Der-Staatszielbestimmungen-Des-Deutschen-Grundgesetz-by-Jona-A-Dohrmann.pdf
    • http://xiixmcuin.linkpc.net/9207201201203203/The-Child-and-the-State-in-India-Child-Labor-and-Education-Policy-in-Comparative-Perspective-by-Myron-Weiner.pdf
    • http://xiixmcuin.linkpc.net/9204209209206207/Milk-Composition-Production-and-Biotechnology-Biotechnology-in-Agriculture-Biotechnology-in-Agriculture-by-C-G-Prosser.pdf
    • http://xiixmcuin.linkpc.net/5201209208203208/Access-Points-An-Institutional-Theory-of-Policy-Bias-and-Policy-Complexity-by-Sean-D-Ehrlich.pdf
    • http://xiixmcuin.linkpc.net/9201206208203208/The-Policy-Makers-Shaping-American-Foreign-Policy-from-1947-to-the-Present-by-Anna-Kasten-Nelson.pdf
    • http://xiixmcuin.linkpc.net/2207205205207202/Narratology-Introduction-to-the-Theory-of-Narrative-by-Mieke-Bal.pdf
    • http://xiixmcuin.linkpc.net/2203200208205203/Loving-Yusuf-Conceptual-Travels-from-Present-to-Past-by-Mieke-Bal.pdf
    • http://xiixmcuin.linkpc.net/1201207202208206202/de-Vlaams-Belgische-Gebarentaal-Een-Eerste-Verkenning-by-Mieke-Van-Herreweghe.pdf
    • http://xiixmcuin.linkpc.net/6204201202206200/Neomonism-by-Dino-Meurs.pdf
    • http://xiixmcuin.linkpc.net/6204201201206201/Demain-je-meurs-by-Orianne-Papin.pdf
    • http://xiixmcuin.linkpc.net/6204201202204208/C-est-ce-soir-que-tu-meurs-by-Cecile-Bonnet.pdf
    • http://xiixmcuin.linkpc.net/6204201202209206/One-Way-Ticket-to-Berlin-by-John-Meurs.pdf
    • http://xiixmcuin.linkpc.net/6204201202200202/Aime-ou-meurs-by-Alexander-Strauch.pdf
    • http://xiixmcuin.linkpc.net/2208207208205201/Legends-of-the-Mountain-State-2-More-Ghostly-Tales-from-the-State-of-West-Virginia-by-Michael-Knost.pdf
    • http://xiixmcuin.linkpc.net/5201202201209200/The-Sympathetic-State-Disaster-Relief-and-the-Origins-of-the-American-Welfare-State-by-Michele-Landis-Dauber.pdf
    • http://xiixmcuin.linkpc.net/5200205201203200/Worshipping-the-State-How-Liberalism-Became-Our-State-Religion-by-Benjamin-Wiker.pdf
    • http://xiixmcuin.linkpc.net/6205209207204/State-by-State-A-Panoramic-Portrait-of-America-by-Matt-Weiland.pdf
    • http://xiixmcuin.linkpc.net/9204209209206207/Milk-Composition-Production-and-Biotechno