Malicious PDF — malware analysis report

Static analysis result for SHA-256 9578ad6fa16c386a…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 04:48:33 +01:00 Authoring application: mPDF 5.7
MD5: 4ae979e3619e47ddaf1d82ce3e4ffc47 SHA-1: 4f4c412b4439deb0fd0c9c37107eea1f2ba71a09 SHA-256: 9578ad6fa16c386a6eac770bf29b77c3202053f26f150d94332ee9499453af5f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. This indicates the document is designed to host a large number of external links. The embedded URLs, while individually marked as benign, collectively form a link farm, suggesting a potential distribution or phishing mechanism. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7200207207209208/The-Book-Thief-A-Novel-by-Markus-Zusak-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/6209208209206201/The-Storied-Life-of-A-J-Fikry-A-Novel-by-Gabrielle-Zevin-Trivia-on-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/7201200201209204/The-Maze-Runner-by-James-Dashner-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/1200208204202202209/My-Brilliant-Friend-A-Novel-By-Elena-Ferrante-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/9202200206208204/And-the-Mountains-Echoed-By-Khaled-Hosseini-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/1200207200200208207/The-Rosie-Effect-A-Novel-by-Graeme-Simsion-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/1201205206202201205/Where-d-You-Go-Bernadette-A-Novel-by-Maria-Semple-Trivia-On-Books-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/1201207202205206205/I-Am-Malala-By-Malala-Yousafzai-and-Christina-Lamb-Trivia-On-Books-The-Girl-Who-Stood-Up-for-Education-and-Was-Shot-by-the-Taliban-by-Trivion-Books.pdf
    • http://xiixmcuin.linkpc.net/3206209201205/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/3202208207202200/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/7203203200209204/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/4200208202206/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/2209202201201209/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/5202208202209/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/5208207203205/The-Book-Thief-by-Markus-Zusak.pdf
    • http://xiixmcuin.linkpc.net/7200207208200200/The-Book-Thief-by-Markus-Zusak-A-review-by-Noman-salehzada.pdf
    • http://xiixmcuin.linkpc.net/7200207207209209/A-Guide-to-The-Book-Thief-by-Markus-Zusak-by-Liss-Ross.pdf
    • http://xiixmcuin.linkpc.net/5209207208204206/The-Book-Thief-by-Markus-Zusak----Review-by-Expert-Book-Reviews.pdf
    • http://xiixmcuin.linkpc.net/7200207208204206/Summary-of-The-Book-Thief-by-Markus-Zusak-Conversation-Starters-by-BookHabits.pdf
    • http://xiixmcuin.linkpc.net/7200207208204202/A-Study-Guide-for-Markus-Zusak-s-the-Book-Thief-by-Cengage-Learning-Gale.pdf
    • http://xiixmcuin.linkpc.net/1201207202205206205/I-Am-Malala-By-Malala-Yousafzai-and-Christina-Lamb-Trivia-On-Books-The-Girl-Who-Stood-Up-for