Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5966e0c2c12ac45…

MALICIOUS

PDF

18.6 KB Created: 2019-05-07 04:52:04 +01:00 Authoring application: mPDF 5.7
MD5: 3ffd77b5050438e95875643d242abeb0 SHA-1: e42abc5ecd21db17dc548d68496c4fc97715ba7b SHA-256: a5966e0c2c12ac45f0bdb85b47fac509078bd13c5bf981a662a9fe4119a27a62
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting the document's purpose is to drive traffic to these external links. No scripts were extracted from this sample. The URLs themselves appear to be benign, but the sheer volume and structure suggest a malicious intent to redirect users.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1205204201204200/A-Conflict-of-Visions-Ideological-Origins-of-Political-Struggles-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/2207203209206206/The-Housing-Boom-and-Bust-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/2205204205201204/Economic-Facts-and-Fallacies-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/3203201204203203/The-Quest-for-Cosmic-Justice-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/6200203209203/The-Quest-for-Cosmic-Justice-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/8208204200208/Economic-Facts-and-Fallacies-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/1207209201203204/Trickle-Down-Theory-and-Tax-Cuts-for-the-Rich-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/6202206209206/Applied-Economics-Thinking-Beyond-Stage-One-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/2205201204205206/Race-And-Culture-A-World-View-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/1201205200208207/The-Balfour-Declaration-The-Origins-of-the-Arab-Israeli-Conflict-by-Jonathan-Schneer.pdf
    • http://xiixmcuin.linkpc.net/1201208209206206207/Jerusalem-1913-The-Origins-of-the-Arab-Israeli-Conflict-by-Amy-Dockser-Marcus.pdf
    • http://xiixmcuin.linkpc.net/5209201200200202/The-Origins-And-Development-Of-The-Ottoman-afavid-Conflict-906-962-1500-1555-by-Adel-Allouche.pdf
    • http://xiixmcuin.linkpc.net/1205204201201204/The-Vision-of-the-Anointed-Self-Congratulation-as-a-Basis-for-Social-Policy-by-Thomas-Sowell.pdf
    • http://xiixmcuin.linkpc.net/7206202205203201/Political-Conflict-and-Constitutional-Change-in-Puerto-Rico-1898-1952-by-Alfredo-Montalvo-Barbot.pdf
    • http://xiixmcuin.linkpc.net/4202204204203200/The-Creation-of-the-Media-Political-Origins-of-Modern-Communications-by-Paul-Starr.pdf
    • http://xiixmcuin.linkpc.net/2204208204207209/The-Origins-of-Political-Order-From-Prehuman-Times-to-the-French-Revolution-by-Francis-Fukuyama.pdf
    • http://xiixmcuin.linkpc.net/1200203201208207209/The-Art-of-War-Spirituality-for-Conflict-Annotated-amp-Explained-by-Thomas-Huynh.pdf
    • http://xiixmcuin.linkpc.net/3206209201202209/The-Old-Southwest-1795-1830-Frontiers-in-Conflict-by-Thomas-D-Clark.pdf
    • http://xiixmcuin.linkpc.net/2207204204200207/Discourse-on-the-Origins-of-Inequality-Second-Discourse-Polemics-and-Political-Economy-by-Jean-Jacques-Rousseau.pdf
    • http://xiixmcuin.linkpc.net/2206200201209207/Political-Writings-by-Thomas-Paine.pdf
    • http://xiixmcuin.linkpc.net/5209201200200202/The-Origins-And-Development-Of-The-Ottoman-afavid-Conflict-906-962-1500-1555-by-Adel-Al