Malicious PDF — malware analysis report

Static analysis result for SHA-256 5863bda0b294d380…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 01:40:16 +01:00 Authoring application: mPDF 5.7
MD5: 7070df0b7ec57f3f50000328fcb746fd SHA-1: 278dc9e1641fba987bbc7cc9629cbfe9d34359d3 SHA-256: 5863bda0b294d3804c6ac57b1c1528b6a763c1173a0b0374b7cfa26111f22fe7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links, forming a link farm. The links point to various PDF files hosted on the `xiixmcuin.linkpc.net` domain, which is a dynamic DNS service. This suggests a tactic to artificially inflate search engine rankings or to distribute content through a large number of seemingly unrelated documents. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2204207207201208/Ceri-s-journey-Angels-by-Linn-B-Halton.pdf
    • http://xiixmcuin.linkpc.net/1200204209204206209/A-Cottage-in-the-Country-by-Linn-B-Halton.pdf
    • http://xiixmcuin.linkpc.net/8206204200202/Clara-s-Christmas-Journey-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/8206201209205/Ava-and-Zeke-s-New-Home-Amish-Forever-A-New-Journey-1-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/8206207208201/Trouble-with-Puppy-Mills-Amish-Forever-A-New-Journey-4-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/8206200200203/Zeke-s-Past-Returns-Amish-Forever-A-New-Journey-5-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/2207205202202201/Paradigm-by-Ceri-A-Lowe.pdf
    • http://xiixmcuin.linkpc.net/3201201201205209/Cupcakes-by-Ceri-Hadda.pdf
    • http://xiixmcuin.linkpc.net/5208204201206/Of-Beetles-amp-Angels-A-Boy-s-Remarkable-Journey-from-a-Refugee-Camp-to-Harvard-by-Mawi-Asgedom.pdf
    • http://xiixmcuin.linkpc.net/9209205207202/Of-Beetles-and-Angels-A-Boy-s-Remarkable-Journey-from-a-Refugee-Camp-to-Harvard-by-Mawi-Asgedom.pdf
    • http://xiixmcuin.linkpc.net/2200209206201203/Lauri-Foster-by-Frank-Linn.pdf
    • http://xiixmcuin.linkpc.net/1200201202204206/A-Blessed-Child-by-Linn-Ullmann.pdf
    • http://xiixmcuin.linkpc.net/3206203202206205/Healing-with-the-Angels-How-the-Angels-Can-Assist-You-in-Every-Area-of-Your-Life-by-Doreen-Virtue.pdf
    • http://xiixmcuin.linkpc.net/3202205201200204/That-None-May-Be-Lost-Mark-Miller-s-One-15-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/3205205209207208/Betting-on-Love-by-Alyssa-Linn-Palmer.pdf
    • http://xiixmcuin.linkpc.net/3201207202205201/Ashes-of-Angels-Of-Angels-and-Demons-3-by-Michele-Hauf.pdf
    • http://xiixmcuin.linkpc.net/1208201201206205/Until-Angels-Close-My-Eyes-Angels-3-by-Lurlene-McDaniel.pdf
    • http://xiixmcuin.linkpc.net/3203202205208203/The-Paris-Game-Le-Chat-Rouge-1-by-Alyssa-Linn-Palmer.pdf
    • http://xiixmcuin.linkpc.net/2200201209202205/The-Trouble-with-Angels-Angels-Everywhere-2-by-Debbie-Macomber.pdf
    • http://xiixmcuin.linkpc.net/1200206209200205/Angels-Watching-Over-Me-Angels-1-by-Lurlene-McDaniel.pdf
    • http://xiixmcuin.linkpc.net/9209205207202/Of-Beetles-and-Ang