Malicious PDF — malware analysis report

Static analysis result for SHA-256 9eb57f00f2c96817…

MALICIOUS

PDF

20.3 KB Created: 2019-05-02 18:05:08 +01:00 Authoring application: mPDF 5.7
MD5: 41098f229a5b9ef287f7da41d7ddd689 SHA-1: 5a4e17e5cbe9615615272e0d69e2ef2116f038d1 SHA-256: 9eb57f00f2c96817e25069765b553091cef1c6e31c13d963a00210a6029d30b7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample. The primary attack pattern involves leveraging a link farm within a PDF document.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4204207204205202/It-s-a-Long-Story-My-Life-by-Willie-Nelson.pdf
    • http://xiixmcuin.linkpc.net/7209200205201/It-s-a-Long-Story-My-Life-by-Willie-Nelson.pdf
    • http://xiixmcuin.linkpc.net/2203209201205200/The-Tao-of-Willie-A-Guide-to-the-Happiness-in-Your-Heart-by-Willie-Nelson.pdf
    • http://xiixmcuin.linkpc.net/2205208209204203/155-World-s-Funniest-Yo-Mama-Dirty-Jokes-Yo-Mama-Funny-Dirty-Filthy-Joke-Book-For-Adults---Uncensored-edition-World-s-Funniest-Jokes-2-by-Oliver-Oliver-Reed.pdf
    • http://xiixmcuin.linkpc.net/4204201207200209/Outlaw-Waylon-Jennings-Willie-Nelson-Kris-Kristofferson-and-the-Renegades-of-Nashville-by-Michael-Streissguth.pdf
    • http://xiixmcuin.linkpc.net/2206203201206208/Life-s-Work-A-Moral-Argument-for-Choice-by-Willie-Parker.pdf
    • http://xiixmcuin.linkpc.net/7203208201207200/Yo-Mama-Jokes-Bible-350-Funny-amp-Hilarious-Yo-Mama-Jokes-by-Johnny-B-Laughing.pdf
    • http://xiixmcuin.linkpc.net/4207206206201204/The-Facts-of-Life-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/6201205203207201/Facts-Of-Life-by-Pippi-Lionni.pdf
    • http://xiixmcuin.linkpc.net/6201205203202201/Facts-Of-Life-by-Pippo-Lionni.pdf
    • http://xiixmcuin.linkpc.net/4203204202207207/Heidegger-and-a-Hippo-Walk-Through-Those-Pearly-Gates-Using-Philosophy-and-Jokes-to-Explore-Life-Death-the-Afterlife-and-Everything-in-Between-by-Thomas-Cathcart.pdf
    • http://xiixmcuin.linkpc.net/7202203200208205/Patient-Drug-Facts-2004-Published-by-Facts-and-Comparisons-by-Timothy-R-Covington.pdf
    • http://xiixmcuin.linkpc.net/7201207207206205/Random-Facts-1869-Facts-To-Make-You-Want-To-Learn-More-by-Nazar-Shevchenko.pdf
    • http://xiixmcuin.linkpc.net/7203208203201207/Invincible-Vol-5-The-Facts-of-Life-by-Robert-Kirkman.pdf
    • http://xiixmcuin.linkpc.net/7207200201202208/Colorless-Tsukuru-Tazaki-and-His-Years-of-Pilgrimage---101-Book-Facts-1-Fun-Facts-amp-Trivia-Tidbits-by-G-Whiz.pdf
    • http://xiixmcuin.linkpc.net/7205204205203200/Americanah-by-Chimamanda-Ngozi-Adichie-Top-50-Facts-Coutndown-by-Top-50-Facts.pdf
    • http://xiixmcuin.linkpc.net/8206202207208205/Creation-Facts-Of-Life-Revisited-Pb-by-Gary-E-Parker.pdf
    • http://xiixmcuin.linkpc.net/5209202208205201/Knock-Knock-Jokes-for-Kids-301-Hilarious-and-Funny-Knock-Knock-Jokes-by-Lizzy-Burbank.pdf
    • http://xiixmcuin.linkpc.net/5202200202205204/The-New-Corporate-Facts-of-Life-Rethink-Your-Business-to-Transform-Today-s-Challeneges-Into-Tomorrow-s-Profits-by-Diana-Rivenburgh.pdf
    • http://xiixmcuin.linkpc.net/1201205206203208/The-Life-List-by-Lori-Nelson-Spielman.pdf
    • http://xiixmcuin.linkpc.net/4204201207200209/Outlaw-Waylon-Jennings-Willie-Nelson-Kris-Kristofferson-and-the-Renegades-of-Nashville-by-Michael