Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c2e54654fa3b674…

MALICIOUS

PDF

25.5 KB Created: 2019-04-30 18:34:21 +01:00 Authoring application: mPDF 5.7
MD5: 690ef4718560aad0cdcf28a7e1a1f76f SHA-1: 3421391d922337b660afff9984644beee8dd174d SHA-256: 8c2e54654fa3b6744e591c7b034e48753d2f1642274ebed44d1a25cf0d1567be
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. No scripts were extracted from this sample, limiting the ability to determine a more specific attack pattern or family. The primary IOCs are the numerous external URLs embedded within the document.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5203207206207206/World-War-2-Heroes-Jean-Moulin-amp-The-French-Resistance-Forces-in-WWII-World-War-2-World-War-II-WWII-WW2-Jean-Moulin-French-Resistance-Book-1-by-Ryan-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/4207204202207200/World-War-2-History-s-10-Most-Incredible-Women-World-War-II-True-Accounts-Of-Remarkable-Women-Heroes-WWII-history-WW2-War-books-world-war-2-books-war-history-World-war-2-women-by-Stephanie-T-McRae.pdf
    • http://xiixmcuin.linkpc.net/5205200207209200/Resistance-French-Resistance-Book-1-by-Christopher-Nicole.pdf
    • http://xiixmcuin.linkpc.net/5204206200201203/My-Stripes-Were-Earned-In-Hell-A-French-Resistance-Fighter-s-Memoir-Of-Survival-In-A-Nazi-Prison-Camp-by-Jean-Pierre-Renouard.pdf
    • http://xiixmcuin.linkpc.net/3200203207206205/Things-We-Couldn-t-Say-A-Dramatic-Account-of-Christian-Resistance-in-Holland-During-WWII-by-Diet-Eman.pdf
    • http://xiixmcuin.linkpc.net/6203204209201206/Jean-Moulin-l-ultime-myst-re-by-Pierre-P-an.pdf
    • http://xiixmcuin.linkpc.net/5203207206207205/Pierre-Deux-s-French-Country-by-Pierre-Moulin.pdf
    • http://xiixmcuin.linkpc.net/5202201209209201/A-People-s-History-of-the-Second-World-War-Resistance-Versus-Empire-by-Donny-Gluckstein.pdf
    • http://xiixmcuin.linkpc.net/5200200200201206/The-Power-of-the-Zoot-Youth-Culture-and-Resistance-during-World-War-II-by-Luis-Alvarez.pdf
    • http://xiixmcuin.linkpc.net/7200205209207201/Just-Raoul-Adventures-in-the-French-Resistance-by-James-Bacque.pdf
    • http://xiixmcuin.linkpc.net/4204205206200200/Piece-de-Resistance-French-Twist-3-by-Sandra-Byrd.pdf
    • http://xiixmcuin.linkpc.net/3206209204205200/The-Resistance-Man-A-Mystery-of-the-French-Countryside-by-Martin-Walker.pdf
    • http://xiixmcuin.linkpc.net/3208204202205202/Europe-on-Trial-The-Story-of-Collaboration-Resistance-and-Retribution-during-World-War-II-by-Istv-n-De-k.pdf
    • http://xiixmcuin.linkpc.net/3208204200204204/Xavier-A-British-Secret-Agent-with-the-French-Resistance-by-Richard-Heslop.pdf
    • http://xiixmcuin.linkpc.net/4203205204207204/The-Cyclist-A-World-War-2-Novel-World-War-2-Romance-World-War-II-Adventure-Series-Book-1-by-Fred-Nath.pdf
    • http://xiixmcuin.linkpc.net/1204202206205209/When-the-World-Spoke-French-by-Marc-Fumaroli.pdf
    • http://xiixmcuin.linkpc.net/6209202207201200/A-Personal-Journey-Into-the-Quantum-World-God-s-Silent-World-by-Paul-Corriveau-Jean-Paul-Corriveau.pdf
    • http://xiixmcuin.linkpc.net/7200204205203208/Churchill-s-Secret-Warriors-The-Explosive-True-Story-of-The-Special-Forces-Desperadoes-of-WWII-by-Damien-Lewis.pdf
    • http://xiixmcuin.linkpc.net/3209205200208200/The-World-in-My-Kitchen-The-Adventures-of-a-Mostly-French-Woman-in-New-York-by-Colette-Rossant.pdf
    • http://xiixmcuin.linkpc.net/1206205202209202/French-North-Africa-The-Maghrib-Between-Two-World-Wars-by-Jacques-Berque.pdf
    • http://xiixmcuin.linkpc.net/5204206200201203/My-Stripes-Were-Earned-In-Hell-A-French-Resistance-Fighter-s-Memoir-Of-Su