Malicious PDF — malware analysis report

Static analysis result for SHA-256 7dcb7d446f37ea06…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 02:43:46 +01:00 Authoring application: mPDF 5.7
MD5: 7868cb22e83e50f67ecc7af8f6b6fb3f SHA-1: c5d5a4488e632b66aa4552bf84ed5204dde2dc56 SHA-256: 7dcb7d446f37ea06bdf41b5cb4de77971d35e42d880102066f5770422c74b977
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was identified as malicious by ClamAV with the signature Pdf.Dropper.Agent-7193320-0. Static analysis revealed a large number of embedded URLs, forming a link farm. The primary heuristic firing, PDF_SEO_LINK_FARM, indicates that these links are likely used to distribute further malicious content or for SEO manipulation. The dominant host for these links is xiixmcuin.linkpc.net.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7193320-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7193320-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201200209201202206/Loki-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/3207204204202208/Codename-Knockout-Volume-1-The-Devil-You-Say-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/4203209201201208/Thor-Loki-Blood-Brothers-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/5208209201/Bitch-Planet-Vol-2-President-Bitch-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/8205202208206209/Bitch-A-New-Beginning-Bitch-6-by-Deja-King.pdf
    • http://xiixmcuin.linkpc.net/2200207205208203/Last-Bitch-Standing-Bitch-5-by-Deja-King.pdf
    • http://xiixmcuin.linkpc.net/8205202208206208/Queen-Bitch-Bitch-4-by-Deja-King.pdf
    • http://xiixmcuin.linkpc.net/3204202203202204/Bad-Bitch-Bad-Bitch-1-by-Christina-Saunders.pdf
    • http://xiixmcuin.linkpc.net/7201204202206200/Heka-s-Blessing-A-modern-goddess-of-ancient-Egypt-Goddess-of-the-Black-Land-Book-1-by-Alexandria-Grolleau.pdf
    • http://xiixmcuin.linkpc.net/7201204202205201/Sobek-s-Child-A-modern-goddess-of-ancient-Egypt-Goddess-of-the-Black-Land-Book-2-by-Alexandria-Grolleau.pdf
    • http://xiixmcuin.linkpc.net/1200201203205207/Goddess-of-the-Rose-Goddess-Summoning-4-by-P-C-Cast.pdf
    • http://xiixmcuin.linkpc.net/3206200202203/Goddess-of-the-Rose-Goddess-Summoning-4-by-P-C-Cast.pdf
    • http://xiixmcuin.linkpc.net/3204207205207201/One-Night-with-a-Goddess-Goddess-2-by-Judi-McCoy.pdf
    • http://xiixmcuin.linkpc.net/4206208205204206/His-Sea-Goddess-Goddess-Revealed-4-by-Marisa-Chenery.pdf
    • http://xiixmcuin.linkpc.net/3207205209203/Goddess-of-the-Sea-Goddess-Summoning-1-by-P-C-Cast.pdf
    • http://xiixmcuin.linkpc.net/3204207205207200/Almost-a-Goddess-Goddess-1-by-Judi-McCoy.pdf
    • http://xiixmcuin.linkpc.net/1205206208209207/The-Goddess-Prophecies-Books-1-3-The-Goddess-Prophecies-Fantasy-Series-Box-Set-by-Araya-Evermore.pdf
    • http://xiixmcuin.linkpc.net/7204209204202201/Bitch-Planet-Triple-Feature-Vol-1-Bitch-Planet-Triple-Feature-1-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/3206202200204207/The-Goddess-Test-Goddess-Test-1-by-Aimee-Carter.pdf
    • http://xiixmcuin.linkpc.net/2204208206208202/The-Goddess-Test-Goddess-Test-1-by-Aimee-Carter.pdf