Malicious PDF — malware analysis report

Static analysis result for SHA-256 9427e58ceb8f746b…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:42:02 +01:00 Authoring application: mPDF 5.7
MD5: 7371742d3b8151b12275eaa2770653fb SHA-1: 24ac0020a6d73c9a8a9ab1baf6cc20e3952675a4 SHA-256: 9427e58ceb8f746b77b87730a30f8f289d082dbb18280006598ec50eb939efde
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the `xiixmcuin.linkpc.net` domain. This behavior is indicative of a link farm or a lure to download further malicious content. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4205208200205200/Janey-G-Blue-Pearl-Harbor-1941-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/9209201202201200/The-Bombing-of-Pearl-Harbor-1941-I-Survived-4-by-Lauren-Tarshis.pdf
    • http://xiixmcuin.linkpc.net/1201200205208203209/Blizzard-Colorado-1886-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/1201208209208200206/Francesca-Vigilucci-Washington-DC-1913-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/8207203205203200/Anisett-Lundberg-California-1851-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/9203203209200208/Mary-Alice-Peale-Philadelphia-1777-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/2204207202209202/Survival-Cave-In-St-Claire-Pennsylvania-1859-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/4205208200205201/Emma-Eileen-Grove-Vicksburg-Mississippi-1865-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/2205208200204209/Infamy-Pearl-Harbor-and-its-Aftermath-by-John-Toland.pdf
    • http://xiixmcuin.linkpc.net/3203205206201203/Pearl-Harbor-FDR-Leads-the-Nation-Into-War-by-Steven-M-Gillon.pdf
    • http://xiixmcuin.linkpc.net/9200203200206206/Final-Secret-of-Pearl-Harbor-by-Robert-A-Theobald.pdf
    • http://xiixmcuin.linkpc.net/4203206206202204/Tongue-of-War-From-Pearl-Harbor-to-Nagasaki-by-Tony-Barnstone.pdf
    • http://xiixmcuin.linkpc.net/5209203203209205/The-Pacific-War-Companion-From-Pearl-Harbor-to-Hiroshima-by-Daniel-Marston.pdf
    • http://xiixmcuin.linkpc.net/7208206204200209/The-Desperate-Diplomat-Saburo-Kurusu-s-Memoir-of-the-Weeks-before-Pearl-Harbor-by-J-Garry-Clifford.pdf
    • http://xiixmcuin.linkpc.net/7201200208205209/Lightning-Strike-The-Secret-Mission-to-Kill-Admiral-Yamamoto-and-Avenge-Pearl-Harbor-by-Donald-A-Davis.pdf
    • http://xiixmcuin.linkpc.net/8207206202208205/The-Flying-Tigers-The-Untold-Story-of-the-American-Pilots-Who-Waged-a-Secret-War-Against-Japan-Before-Pearl-Harbor-by-Samuel-Kleiner.pdf
    • http://xiixmcuin.linkpc.net/3205201200200200/Pearl-Harbor-Date-of-Infamy-Date-to-Remember-by-Jon-J-Cardwell.pdf
    • http://xiixmcuin.linkpc.net/1202204202200206/The-Light-of-the-Blue-Pearl-by-K-C-Hawke.pdf
    • http://xiixmcuin.linkpc.net/1200209206201208203/Katie-and-the-Mustang-2-Hoofbeats-Katie-and-the-Mustang-2-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/2207207202201203/The-Blue-Blazes-Mookie-Pearl-1-by-Chuck-Wendig.pdf
    • http://xiixmcuin.linkpc.net/4203206206202204/Tongue-of-War