Malicious PDF — malware analysis report

Static analysis result for SHA-256 88db2e86e81336ad…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 02:32:03 +01:00 Authoring application: mPDF 5.7
MD5: 74509c5200422eab7edc23d98040a12d SHA-1: 41b144e1a43a4f2c6e08ab56e453beffe56b894a SHA-256: 88db2e86e81336adeb60b0c74399c9e2286b20aace96964a4f7d023bb9757fff
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. While most of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a potential for distributing malicious content or engaging in SEO spam. The document body is heavily obfuscated, preventing a clear understanding of its direct user-facing purpose beyond the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201209204208201208/The-Pout-Pout-Fish-Wipe-Clean-Workbook-ABC-1-20-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204207205202/The-Pout-Pout-Fish-book-and-CD-storytime-set-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204208202200/Trick-or-Treat-Pout-Pout-Fish-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204206208204/The-Pout-Pout-Fish-Far-Far-from-Home-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204206208201/The-Not-Very-Merry-Pout-Pout-Fish-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204207204205/The-Pout-Pout-Fish-Tank-A-Book-and-Fish-Set-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1208205200206207/The-Pout-Pout-Fish-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/3200202200201206/Better-Not-Pout-by-Annabeth-Albert.pdf
    • http://xiixmcuin.linkpc.net/1200204204202201207/Yell-and-Shout-Cry-and-Pout-A-Kid-s-Guide-to-Feelings-by-Peggy-Kruger-Tietz.pdf
    • http://xiixmcuin.linkpc.net/1208205203201202/Picture-Day-Perfection-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201209204208208201/Pippa-and-Percival-Pancake-and-Poppy-Four-Peppy-Puppies-by-Deborah-Diesen.pdf
    • http://xiixmcuin.linkpc.net/1201206209207207206/Fish---Noch-mehr-Fish---F-r-immer-Fish-Dreimal-ungew-hnliche-Motivation-in-einem-Band-by-Stephen-C-Lundin.pdf
    • http://xiixmcuin.linkpc.net/8206202205207206/One-Fish-Two-Fish-Red-Fish-Blue-Fish-by-Dr-Seuss.pdf
    • http://xiixmcuin.linkpc.net/7204203207203202/One-Fish-Two-Fish-Red-Fish-Blue-Fish-by-Dr-Seuss.pdf
    • http://xiixmcuin.linkpc.net/1206207207201207/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1202202202206201/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/9204207205204/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3201200206207202/The-Dash-Diet-Fish-and-Seafood-Cookbook-30-Delicious-Low-Salt-Fish-and-Seafood-Recipes-for-Lowering-Blood-Pressure-Losing-Weight-and-Improving-Your-Health-by-Sarah-Sophia.pdf
    • http://xiixmcuin.linkpc.net/1201209204208202208/Nach-all-diesen-Jahren-by-Joy-Packer.pdf
    • http://xiixmcuin.linkpc.net/1201209204208202207/Ich-brauchte-diesen-Job-by-Lena-Schreiber.pdf
    • http://xiixmcuin.linkpc.net/1201206209207207206/Fish---Noch-mehr-Fish---F-r-immer-Fish-Dreimal-ungew-hnliche-M