Malicious PDF — malware analysis report

Static analysis result for SHA-256 563036aaf088f3cb…

MALICIOUS

PDF

13.3 KB Created: 2019-05-02 00:22:15 +01:00 Authoring application: mPDF 5.7
MD5: 743defc551f5fc1097e7915e6d2157f9 SHA-1: 9ba30c2a6086b32c86a752edd6a44a7c25198032 SHA-256: 563036aaf088f3cba0033f9b6e061e75e1b71159a0d5ad4aeba2f98e29a10d7e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented in a way that suggests they are book titles, a common social engineering tactic to entice users to click. The embedded URLs are reconstructed from the document body, indicating a link farm designed to redirect users to potentially malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4204205209203201/Fireworks-Nine-Profane-Stories-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3203209202204/The-Bloody-Chamber-and-Other-Stories-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/1209203208209204/The-Bloody-Chamber-and-Other-Stories-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3202203209204207/Love-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3209204209205205/Nights-at-the-Circus-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/1207203202203203/Nights-at-the-Circus-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3209208205209206/Saints-And-Strangers-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3205205203203/Nights-at-the-Circus-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/8200207206207/The-Sadeian-Woman-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/2209202202206208/The-Company-of-Wolves-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/2206203209208/Saints-and-Strangers-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/4207201200201207/The-Magic-Toyshop-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/2201203208202/The-Invention-of-Angela-Carter-A-Biography-by-Edmund-Gordon.pdf
    • http://xiixmcuin.linkpc.net/1201203208204203201/Expletives-Deleted-Selected-Writings-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/4207200202206203/Shaking-a-Leg-Collected-Journalism-and-Writings-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/3205208208202206/The-Infernal-Desire-Machines-of-Doctor-Hoffman-by-Angela-Carter.pdf
    • http://xiixmcuin.linkpc.net/9205208205206201/The-Infernal-Desire-Machines-of-Angela-Carter-by-Jeff-VanderMeer.pdf
    • http://xiixmcuin.linkpc.net/4207200203207205/Flesh-and-the-Mirror-Essays-on-the-Art-of-Angela-Carter-by-Lorna-Sage.pdf
    • http://xiixmcuin.linkpc.net/2204207200207209/Love-Like-Fireworks-Love-Like-Fireworks-1-by-Lauren-Melinda.pdf
    • http://xiixmcuin.linkpc.net/4208200209209205/The-Infernal-Desires-Of-Angela-Carter-Fiction-Femininity-Feminism-by-Joseph-Bristow.pdf