Malicious PDF — malware analysis report

Static analysis result for SHA-256 58606da42c21cbce…

MALICIOUS

PDF

16.9 KB Created: 2020-02-20 00:06:45 +00:00 Authoring application: mPDF 5.7
MD5: 778d7ab8cf7da4d451d2a359b7b83a95 SHA-1: ad4f6d794b030cb358d62229826735d787da552b SHA-256: 58606da42c21cbceefd8fe045066a26250359e8e8127302569fba1b6835ed22c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to direct users to a compromised site. No scripts were extracted, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2207203204205208/Cobalt-City-Dark-Carnival-by-Nathan-Crowder.pdf
    • http://xiixmcuin.linkpc.net/4205205204201201/Cobalt-Valentine-amp-Lovelace-Mystery-2-by-Nathan-Aldyne.pdf
    • http://xiixmcuin.linkpc.net/4204204203206205/Storm-Wine-by-Nathan-Crowder.pdf
    • http://xiixmcuin.linkpc.net/5202205207205204/Chanson-Noir-Protectorate-1-by-Nathan-Crowder.pdf
    • http://xiixmcuin.linkpc.net/3209207200209200/Cobalt-City-Double-Feature-by-Erik-Scott-de-Bie.pdf
    • http://xiixmcuin.linkpc.net/2201205205207206/Cobalt-Blue-by-Peggy-Payne.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas-Engagement-A-Bride-for-Christmas-by-Carole-Mortimer.pdf
    • http://xiixmcuin.linkpc.net/2208206201201/An-Almost-Perfect-Christmas-Ocean-City-Boardwalk-4-by-Donna-Fasano.pdf
    • http://xiixmcuin.linkpc.net/2204201209204/The-Underground-Abductor-An-Abolitionist-Tale-about-Harriet-Tubman-Nathan-Hale-s-Hazardous-Tales-5-by-Nathan-Hale.pdf
    • http://xiixmcuin.linkpc.net/3208204206209208/24-1-Christmas-Tales-Butterfly-Adventures-in-Santa-s-Secret-City-by-Alexander-Ruth.pdf
    • http://xiixmcuin.linkpc.net/4206209209204204/All-a-Cowboy-Wants-for-Christmas-Waiting-for-Christmas-His-Christmas-Wish-Once-Upon-a-Frontier-Christmas-by-Judith-Stacy.pdf
    • http://xiixmcuin.linkpc.net/2204202206207/Treaties-Trenches-Mud-and-Blood-Nathan-Hale-s-Hazardous-Tales-4-by-Nathan-Hale.pdf
    • http://xiixmcuin.linkpc.net/2209207207202/Donner-Dinner-Party-Nathan-Hale-s-Hazardous-Tales-3-by-Nathan-Hale.pdf
    • http://xiixmcuin.linkpc.net/1205207207201208/Parched-by-Melanie-Crowder.pdf
    • http://xiixmcuin.linkpc.net/3203202206202202/A-Nearer-Moon-by-Melanie-Crowder.pdf
    • http://xiixmcuin.linkpc.net/3209207201209203/The-Lighthouse-Between-the-Worlds-by-Melanie-Crowder.pdf
    • http://xiixmcuin.linkpc.net/6203202206206/Mystical-Union-by-John-Crowder.pdf
    • http://xiixmcuin.linkpc.net/6204209201204205/Sweet-Charity-by-Sherri-Crowder.pdf
    • http://xiixmcuin.linkpc.net/5203205208208209/Tyran-a-Wolf-s-Story-by-Michael-Crowder.pdf
    • http://xiixmcuin.linkpc.net/2202206201208205/One-Dead-Spy-Nathan-Hale-s-Hazardous-Tales-1-by-Nathan-Hale.pdf
    • http://xiixmcuin.linkpc.net/2204201209204/The-Underground-Abductor-An-Abolitionist-Tale-about-Harriet