Malicious PDF — malware analysis report

Static analysis result for SHA-256 91e9a587a487fa9d…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 19:10:19 +01:00 Authoring application: mPDF 5.7
MD5: 60f229b27c4fabbdeb341a79fd1625b4 SHA-1: 6e447071b3d5cfd8c0e2bff3d7c338793beb139f SHA-256: 91e9a587a487fa9d6114798d534198ebcf789b3afb69a169de9143a9f5c52c13
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document was identified as malicious due to a critical heuristic firing for a large number of embedded external links. These links, such as http://xiixmcuin.linkpc.net/1200205201201206204/To-Protect-I-Robot-Reichert-1-by-Mickey-Zucker-Reichert.pdf, likely serve as a link farm to distribute further malicious content or lead users to phishing pages. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200205201201206204/To-Protect-I-Robot-Reichert-1-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/3208209207209209/Child-of-Thunder-The-Last-of-the-Renshai-3-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/1205206202200208/Beyond-Ragnarok-Renshai-Chronicles-1-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/1205208201205201/The-Children-of-Wrath-Renshai-Chronicles-3-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/1200205201203200206/Dragonrank-Master-Bifrost-Guardians-3-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/3201204209209204/Fields-of-Wrath-Renshai-Saga-2-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/2201205200201200/The-Return-of-Nightfall-Nightfall-2-by-Mickey-Zucker-Reichert.pdf
    • http://xiixmcuin.linkpc.net/5207209203201/HIDDEN-MICKEY-3-Wolf-The-Legend-of-Tom-Sawyer-s-Island-Hidden-Mickey-3-by-Nancy-Temple-Rodrigue.pdf
    • http://xiixmcuin.linkpc.net/6200203205202/HIDDEN-MICKEY-4-Wolf-Happily-Ever-After-Hidden-Mickey-4-by-Nancy-Temple-Rodrigue.pdf
    • http://xiixmcuin.linkpc.net/4201201204205/The-New-Adventures-of-Mickey-Spillane-s-Mike-Hammer-Vol-2-The-Little-Death-by-Mickey-Spillane.pdf
    • http://xiixmcuin.linkpc.net/1201200207208209208/Darin-Mickey-Stuff-I-Gotta-Remember-Not-to-Forget-by-Darin-Mickey.pdf
    • http://xiixmcuin.linkpc.net/3200204200206208/The-Legend-of-Mickey-Tussler-Mickey-Tussler-1-by-Frank-Nappi.pdf
    • http://xiixmcuin.linkpc.net/1201206201203206/HIDDEN-MICKEY-ADVENTURES-3-The-Mermaid-s-Tale-Hidden-Mickey-Adventures-3-by-Nancy-Temple-Rodrigue.pdf
    • http://xiixmcuin.linkpc.net/9202201201201/HIDDEN-MICKEY-ADVENTURES-1-Peter-and-the-Wolf-Hidden-Mickey-Adventures-1-by-Nancy-Temple-Rodrigue.pdf
    • http://xiixmcuin.linkpc.net/2201205201204/Museum-of-Accidents-by-Rachel-Zucker.pdf
    • http://xiixmcuin.linkpc.net/1200200205203208202/Benny-Blu---Zucker-Aus-der-R-be-in-die-T-te-by-Petra-Stubenrauch.pdf
    • http://xiixmcuin.linkpc.net/4201207206205204/Spirit-Warrior-Spirit-Pass-2-by-S-E-Smith.pdf
    • http://xiixmcuin.linkpc.net/5207200205/The-Simplicity-of-Cider-by-Amy-E-Reichert.pdf
    • http://xiixmcuin.linkpc.net/1200201204205209206/Krebszellen-fressen-Zucker-und-f-rchten-Pflanzen-by-Imre-Kusztrich.pdf
    • http://xiixmcuin.linkpc.net/1201204203207203203/Goodbye-Zucker-Zuckerfrei-gl-cklich-in-8-Wochen---Mit-108-Rezepten-by-Sarah-Wilson.pdf
    • http://xiixmcuin.linkpc.net/5207209203201/HIDDEN-MICKEY-3-Wolf-The-Legend-of-Tom-Sawyer-s-Island-Hidden-Mic