Malicious PDF — malware analysis report

Static analysis result for SHA-256 943344dc7dfe4638…

MALICIOUS

PDF

18.5 KB Created: 2019-05-06 16:39:13 +01:00 Authoring application: mPDF 5.7
MD5: 430a313fd9881e652d886ea739fd650e SHA-1: 3215a0e099c3489ce9fcd515561d9275e8e8e74c SHA-256: 943344dc7dfe4638c219fd6ab5d0a825394699b94c15a172d94391b294e24560
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs pointing to external PDF documents. The heuristic PDF_SEO_LINK_FARM indicates this is a link farm designed to direct users to numerous external resources. While the URLs themselves are marked as benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent to distribute or redirect users to potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7208204209203209/Serie-Televisive-Francesi-Galactik-Football-Summer-Crush-Kung-Foot-Summer-Dreams-Highlander-Julie-Lescaut-Highlander-The-Raven-15love-by-Fonte-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/2200203202208/A-Highlander-s-Passion-Highlander-s-Beloved-2-by-Vonnie-Davis.pdf
    • http://xiixmcuin.linkpc.net/1207204203203207/A-Highlander-s-Obsession-Highlander-s-Beloved-1-by-Vonnie-Davis.pdf
    • http://xiixmcuin.linkpc.net/3204201201207205/Forbidden-Highlander-Highlander-Trilogy-2-by-Donna-Fletcher.pdf
    • http://xiixmcuin.linkpc.net/3206203200208/Spell-of-the-Highlander-Highlander-7-by-Karen-Marie-Moning.pdf
    • http://xiixmcuin.linkpc.net/8204209205204205/O-Toque-do-Highlander-Highlander-3-by-Karen-Marie-Moning.pdf
    • http://xiixmcuin.linkpc.net/4206206205200204/Deception-of-a-Highlander-Highlander-1-by-Madeline-Martin.pdf
    • http://xiixmcuin.linkpc.net/1202202205200/Wedding-the-Highlander-Highlander-3-by-Janet-Chapman.pdf
    • http://xiixmcuin.linkpc.net/2207209204206205/Seduced-by-the-Highlander-Highlander-3-by-Julianne-MacLean.pdf
    • http://xiixmcuin.linkpc.net/8205204208207/Highlander-for-the-Holidays-Highlander-8-by-Janet-Chapman.pdf
    • http://xiixmcuin.linkpc.net/2200204206205207/How-a-Scot-Surrenders-to-a-Lady-Highlander-Vows-Entangled-Hearts-5-by-Julie-Johnstone.pdf
    • http://xiixmcuin.linkpc.net/4207205202201203/When-a-Laird-Loves-a-Lady-Highlander-Vows-Entangled-Hearts-Book-1-by-Julie-Johnstone.pdf
    • http://xiixmcuin.linkpc.net/6209201203200203/Kaitlyn-and-the-Highlander-Kaitlyn-and-the-Highlander-1-by-Diana-Knightley.pdf
    • http://xiixmcuin.linkpc.net/3207201201202203/Summer-s-Journey-Volume-Two---Alphabetical-Assignation-Summer-s-Journey-2-by-Summer-Daniels.pdf
    • http://xiixmcuin.linkpc.net/1207205205207207/One-Summer-with-Autumn-by-Julie-Reece.pdf
    • http://xiixmcuin.linkpc.net/2201207203205208/The-Summer-of-Living-Dangerously-by-Julie-Cohen.pdf
    • http://xiixmcuin.linkpc.net/4201202202200/Summer-s-Crossing-Iron-Fey-3-5-by-Julie-Kagawa.pdf
    • http://xiixmcuin.linkpc.net/3206203202209208/Boys-of-Summer-by-Julie-Elizabeth-Leto.pdf
    • http://xiixmcuin.linkpc.net/1200204201/Suddenly-One-Summer-FBI-US-Attorney-6-by-Julie-James.pdf
    • http://xiixmcuin.linkpc.net/8204209207203201/Belgian-Football-Clubs-Standard-Liege-K-A-A-Gent-Kv-Mechelen-K-R-C-Genk-Football-in-Belgium-S-Du-Pays-de-Charleroi-Lierse-S-K-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/2207209204206205/Seduced-by-the-Highla