Malicious PDF — malware analysis report

Static analysis result for SHA-256 887bc97d78fc5309…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 17:47:32 +01:00 Authoring application: mPDF 5.7
MD5: 3b268d6eae7c1380797a48c3700620f1 SHA-1: f86d8b3279435f926d88dba7df53e7a4bf039e97 SHA-256: 887bc97d78fc53092ad3a37944e616ad7030b7ae9d9daa5a5affe0dad8554e72
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents. The heuristic 'PDF_SEO_LINK_FARM' indicates a link farm strategy, with the dominant host being 'xiixmcuin.linkpc.net'. While the URLs themselves are marked as benign, the sheer volume and the nature of the hosting domain suggest a malicious intent to drive traffic or potentially distribute further content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkp
    • http://xiixmcuin.linkpc.net/1205206206209207/Are-All-the-Giants-Dead-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/5206204207202206/Six-Mary-Westmacott-Novels-Giants-Bread-Absent-in-the-Spring-Unfinished-Portrait-The-Rose-and-the-Yew-Tree-A-Daughter-s-a-Daughter-The-Burden-by-Mary-Westmacott.pdf
    • http://xiixmcuin.linkpc.net/6206206207209/Bedknob-and-Broomstick-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/9209201202200205/Bonfires-and-Broomsticks-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/4209204200201207/Bed-Knob-and-Broomstick-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/2202202201205205/The-Complete-Adventures-of-the-Borrowers-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/5205209204200202/True-Blood-Collection-Dead-Reckoning-Dead-in-the-Family-a-Touch-of-Dead-Dead-and-Gone-Dead-to-the-World-Dead-as-a-Doornail-All-Together-Dead-and-More-by-Charlaine-Harris.pdf
    • http://xiixmcuin.linkpc.net/3207200205204203/A-People-and-a-Nation-A-History-of-the-United-States-To-1877-by-Mary-Beth-Norton.pdf
    • http://xiixmcuin.linkpc.net/1205209209204205/Giants-Star-Giants-3-by-James-P-Hogan.pdf
    • http://xiixmcuin.linkpc.net/1203203203207201/The-Borrowers-Afield-The-Borrowers-2-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/2200208206205208/The-Borrowers-Avenged-The-Borrowers-5-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/3201207202207/The-Borrowers-The-Borrowers-1-by-Mary-Norton.pdf
    • http://xiixmcuin.linkpc.net/2200205203209203/Newes-from-the-Dead-by-Mary-Hooper.pdf
    • http://xiixmcuin.linkpc.net/8207203207207/The-Dead-Man-in-Indian-Creek-by-Mary-Downing-Hahn.pdf
    • http://xiixmcuin.linkpc.net/4200207204205205/Dead-Monks-and-Shady-Deals-by-Mary-Arrigan.pdf
    • http://xiixmcuin.linkpc.net/5203204202200/All-the-Dead-Lie-Down-Molly-Cates-3-by-Mary-Willis-Walker.pdf
    • http://xiixmcuin.linkpc.net/2208208204207201/Claiming-the-Evil-Dead-Soul-Catcher-1-by-Mary-Abshire.pdf
    • http://xiixmcuin.linkpc.net/9206204204205202/Dead-Storage-A-Maggie-McDonald-Mystery-3-by-Mary-Feliz.pdf
    • http://xiixmcuin.linkpc.net/5202208208207/The-Dead-Don-t-Get-Out-Much-A-Camilla-MacPhee-Mystery-5-by-Mary-Jane-Maffini.pdf
    • http://xiixmcuin.linkpc.net/5209203209203/Dead-Girls-Dead-Boys-Dead-Things-by-Richard-Calder.pdf