Malicious PDF — malware analysis report

Static analysis result for SHA-256 526a1e84e3506802…

MALICIOUS

PDF

16.6 KB Created: 2019-05-02 05:50:26 +01:00 Authoring application: mPDF 5.7
MD5: 662d7d1abb4794b18af096abd8c18898 SHA-1: 7d75596825ce5537b176c133334320d6da18ad82 SHA-256: 526a1e84e350680247e05a558ca260c6341614880ba73434c26594fc6c4ebdeb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to distribute further malware. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3206200208204205/Midnight-Promises-Men-of-Midnight-2-by-Lisa-Marie-Rice.pdf
    • http://xiixmcuin.linkpc.net/3205203202207209/Midnight-Shadows-Midnight-3-5-by-Lisa-Marie-Rice.pdf
    • http://xiixmcuin.linkpc.net/1208203209204200/Midnight-Angel-Midnight-3-by-Lisa-Marie-Rice.pdf
    • http://xiixmcuin.linkpc.net/8200202205205/Midnight-Run-Midnight-2-by-Lisa-Marie-Rice.pdf
    • http://xiixmcuin.linkpc.net/1209207203206204/Midnight-Man-Midnight-1-by-Lisa-Marie-Rice.pdf
    • http://xiixmcuin.linkpc.net/4204204201207209/The-Dark-Warrior-Series-The-Complete-Collection-Contains-Midnight-s-Master-Midnight-s-Lover-Midnight-s-Seduction-Midnight-s-Warrior-Midnight-s-Kiss-Surrender-novella-Dark-Warriors-by-Donna-Grant.pdf
    • http://xiixmcuin.linkpc.net/2206202203207/Midnight-Promises-by-Richard-Chizmar.pdf
    • http://xiixmcuin.linkpc.net/3205200200206208/Stroke-of-Midnight-Midnight-Breed-13-5-1001-Dark-Nights-27-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/4205206208208202/Either-Side-of-Midnight-The-Midnight-Saga-Book-1-by-Tori-de-Clare.pdf
    • http://xiixmcuin.linkpc.net/2205206209209/Deeper-Than-Midnight-Midnight-Breed-9-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/3204207204203/Darker-After-Midnight-Midnight-Breed-10-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/4207200209204/A-Taste-of-Midnight-Midnight-Breed-9-5-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/3203209206200200/Darker-After-Midnight-Midnight-Breed-10-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/1207202204202209/Ashes-of-Midnight-Midnight-Breed-6-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/1206207209209203/Midnight-Kiss-Touched-by-Midnight-1-by-Nancy-Gideon.pdf
    • http://xiixmcuin.linkpc.net/3205207204203207/Midnight-Rising-Midnight-Breed-4-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/3201205204208202/Veil-of-Midnight-Midnight-Breed-5-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/8201201209205205/The-Marquis-At-Midnight-Midnight-Masquerade-1-by-Kate-Harper.pdf
    • http://xiixmcuin.linkpc.net/2209204208202209/Protector-of-Midnight-Chronicles-of-Midnight-1-by-Debbie-Cassidy.pdf
    • http://xiixmcuin.linkpc.net/3204200209208/Midnight-Rising-Midnight-Breed-4-by-Lara-Adrian.pdf
    • http://xiixmcuin.linkpc.net/4204204201207209/The-Dark-Warrior-Series-The-Complete-Collection-Contains-Midnight-s-Master-Midnight-s-Lover-Midnight-s-Seduction-Midnight-s-Warrior-Midnight-s-Kiss-S