Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f89ff5e81e39694…

MALICIOUS

PDF

13.8 KB Created: 2019-04-30 04:17:54 +01:00 Authoring application: mPDF 5.7
MD5: 8592f0e368a4a7a2676b0f0349cd5033 SHA-1: d0b79edb1c67c4c08b24d0df54deb922c265ca83 SHA-256: 8f89ff5e81e39694a438eedf0a05aa36c24fbefa8b2d3cddc6e5624091e24c3d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which are likely used to artificially inflate search engine rankings or direct users to potentially malicious content. The document body confirms the presence of these links, which point to various book titles hosted on the `xiixmcuin.linkpc.net` domain. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3206201202200207/The-Corpse-in-the-Waxworks-Henri-Bencolin-4-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2203207200207202/Castle-Skull-Henri-Bencolin-2-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/6209204207202200/A-John-Dickson-Carr-Trio-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2202209204203203/Papa-La-Bas-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2206208205206200/The-Witch-of-the-Low-Tide-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/1201205204201202/Fire-Burn-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2206208203209206/Captain-Cut-Throat-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2206208201208200/The-Hollow-Man-Dr-Gideon-Fell-6-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/1201202205201208206/Der-Teufel-in-Samt-Roman-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2208200200209208/The-Murder-of-Sir-Edmund-Godfrey-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2208209201200206/The-Crooked-Hinge-Dr-Gideon-Fell-8-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2202207208200204/The-Case-of-the-Constant-Suicides-Dr-Gideon-Fell-13-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/4209202202208203/Till-Death-Do-Us-Part-Dr-Gideon-Fell-15-by-John-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/2201208200202208/Ripped-by-Shelly-Dickson-Carr.pdf
    • http://xiixmcuin.linkpc.net/6208209200201207/Henri-Bergson-The-Philosophy-of-Change-by-Herbert-Wildon-Carr.pdf
    • http://xiixmcuin.linkpc.net/1201209209206206/The-Tinner-s-Corpse-Crowner-John-Mystery-5-by-Bernard-Knight.pdf
    • http://xiixmcuin.linkpc.net/6209204207201208/The-Adventures-of-Dickson-McCunn-by-John-Buchan.pdf
    • http://xiixmcuin.linkpc.net/4205200207209203/Hearing-Her-Voice-A-Case-for-Women-Giving-Sermons-by-John-Dickson.pdf
    • http://xiixmcuin.linkpc.net/4206207203201204/Life-a-la-Henri-Being-the-Memories-of-Henri-Charpentier-by-Henri-Charpentier.pdf
    • http://xiixmcuin.linkpc.net/3200207206203206/The-Creature-in-the-Waxworks-Tales-of-Weird-amp-Lovecraftian-Horror-by-Mark-McLaughlin.pdf
    • http://xiixmcuin.linkpc.net/4209202202208203/Till-Death-Do