Malicious PDF — malware analysis report

Static analysis result for SHA-256 9de63078e87855a1…

MALICIOUS

PDF

18.9 KB Created: 2019-05-07 04:55:29 +01:00 Authoring application: mPDF 5.7
MD5: 49d6d7b604b4436103faf954012a237c SHA-1: 6b02692233a660f9bd4a4ce6a2be5111d2b95329 SHA-256: 9de63078e87855a104ed0358bcbc7418ca6cc083520d991fb24b4296311981e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links pointing to external PDFs hosted on the domain 'xiixmcuin.linkpc.net'. This heuristic firing suggests a link farm or a method to distribute malicious content indirectly. The document body itself is heavily obfuscated, making it difficult to determine the exact lure, but the sheer volume of links indicates a malicious intent to redirect the user. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/9208200208209205/The-Agony-And-The-Exit-Donato-s-Political-Cartoons-by-Andy-Donato.pdf
    • http://xiixmcuin.linkpc.net/5205202208209207/Concrete-Designers-Manual-Tables-and-Diagrams-for-the-Design-of-Reinforced-Concrete-Structures-by-George-A-Hool.pdf
    • http://xiixmcuin.linkpc.net/6203206209200206/Condensed-Silica-Fume-In-Concrete-by-Fip-Commission-On-Concrete.pdf
    • http://xiixmcuin.linkpc.net/1200206202207205200/Works-Issued-by-the-Hakluyt-Society-No-LXXXV-The-Travels-of-Pietro-Della-Valle-in-India-Vol-II-Pp-194-454-by-Pietro-Della-Valle.pdf
    • http://xiixmcuin.linkpc.net/7208203201202205/The-Words-and-Works-of-Jesus-Christ-A-Study-of-the-Life-of-Christ-by-J-Dwight-Pentecost.pdf
    • http://xiixmcuin.linkpc.net/4202203201200202/From-Jesus-to-Christ-The-Origins-of-the-New-Testament-Images-of-Christ-by-Paula-Fredriksen.pdf
    • http://xiixmcuin.linkpc.net/4200205207204205/The-Second-Coming-of-Christ-The-Resurrection-of-the-Christ-Within-You-a-Revelatory-Commentary-on-the-Original-Teachings-of-Jesus-by-Paramahansa-Yogananda.pdf
    • http://xiixmcuin.linkpc.net/1201207205200207203/A-History-of-the-Disciples-of-Christ-the-Society-of-Friends-the-United-Brethren-in-Christ-and-by-bp-Samuel-Peter-Spreng-Benjamin-Bushrod-Tyler.pdf
    • http://xiixmcuin.linkpc.net/9208200209208204/The-Threads-of-Life-by-Donato.pdf
    • http://xiixmcuin.linkpc.net/9208200207200202/Burial-by-Claire-Donato.pdf
    • http://xiixmcuin.linkpc.net/1201207209207209201/Leonardo-La-Gioconda-by-Pietro-C-Marani.pdf
    • http://xiixmcuin.linkpc.net/2206206209208/Visions-of-Middle-Earth-by-Donato-Giancola.pdf
    • http://xiixmcuin.linkpc.net/9208200207200209/Belly-Fat-Blaster-The-How-To-Guide-by-Tony-Donato.pdf
    • http://xiixmcuin.linkpc.net/9208200209208200/Donato-and-the-Cartege-Blade-by-Fiona-Jordan.pdf
    • http://xiixmcuin.linkpc.net/4201200202208201/Visit-My-Alien-Worlds-by-Donato-Giancola.pdf
    • http://xiixmcuin.linkpc.net/6205204208203200/I-Geni-manipolati-di-Adamo-by-Pietro-Buffa.pdf
    • http://xiixmcuin.linkpc.net/8202207200208201/Antiquit-s-d-Herculanum-Tome-III-by-Pietro-Piranesi.pdf
    • http://xiixmcuin.linkpc.net/9208200207205203/Burn-a-Pound-of-Fat-a-Week-The-How-To-Guide-by-Tony-Donato.pdf
    • http://xiixmcuin.linkpc.net/9208200207205205/Perspectives-on-the-Sabbath-Four-Views-by-Christopher-John-Donato.pdf
    • http://xiixmcuin.linkpc.net/1204209201206208/Christ-the-Lord-The-Road-to-Cana-Christ-the-Lord-2-by-Anne-Rice.pdf
    • http://xiixmcuin.linkpc.net/7208203201202205/The-Words-and-Works-of-J