Malicious PDF — malware analysis report

Static analysis result for SHA-256 b15a1bc49863d152…

MALICIOUS

PDF

20.9 KB Created: 2019-04-30 02:17:51 +01:00 Authoring application: mPDF 5.7
MD5: 8be248d6552371d26256002ebaefe625 SHA-1: 1f2d9b1c5e5e8869f97798cf2dab1f73c6c31084 SHA-256: b15a1bc49863d15207ba3d1a8458cdab7b192b20064129c2910ace17a135d8a3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting the document is designed to drive traffic to external sites. While the document body is heavily obfuscated, the presence of numerous URLs points to a social engineering tactic to direct users to potentially malicious content hosted on the `xiixmcuin.linkpc.net` domain. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8207204200201200/Swedish-Christmas-Crafts-by-Helene-S-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/7208200200206201/Crafting-365-Days-of-Crafting-365-Crafting-Patterns-for-365-Days-Crafting-Books-Crafts-DIY-Crafts-Hobbies-and-Crafts-How-to-Craft-Projects-Handmade-Holiday-Christmas-Crafting-Ideas-by-White-Lemon.pdf
    • http://xiixmcuin.linkpc.net/7208200201204200/Night-Before-Christmas-Rubber-Stamp-Storybook-and-Christmas-Crafts-by-Clement-C-Moore.pdf
    • http://xiixmcuin.linkpc.net/8203203201206202/Advent-and-Christmas-Crafts-on-a-Shoestring-Budget-by-Paula-Jobin.pdf
    • http://xiixmcuin.linkpc.net/5200202202206205/Christmas-All-Through-the-House-Crafts-Decorating-Food-by-Carol-Field-Dahlstrom.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas-Engagement-A-Bride-for-Christmas-by-Carole-Mortimer.pdf
    • http://xiixmcuin.linkpc.net/4206209209204204/All-a-Cowboy-Wants-for-Christmas-Waiting-for-Christmas-His-Christmas-Wish-Once-Upon-a-Frontier-Christmas-by-Judith-Stacy.pdf
    • http://xiixmcuin.linkpc.net/8207203205203202/Lundbergisms-by-Debbie-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/9202204204203/I-Don-t-Have-to-Make-Everything-All-Better-by-Gary-B-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/2203200201205205/Bo-Bo-and-Cha-Cha-s-Big-Day-Out-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200205200/The-Rockefeller-Syndrome-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200204205/Severed-Trust-by-George-D-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207203207200207/Cracks-in-the-Constitution-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200201204/LONTAR-2-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200204202/Politicians-and-Other-Scoundrels-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/3207203204201205/The-Christmas-Brides-A-McKettrick-Christmas-A-Creed-Country-Christmas-McKettricks-10-Montana-Creeds-4-by-Linda-Lael-Miller.pdf
    • http://xiixmcuin.linkpc.net/5200202209200203/White-Christmas-Bloody-Christmas-Finally-the-True-Story-of-the-Lawson-Family-Murders-of-Christmas-Day-1929-by-M-Bruce-Jones.pdf
    • http://xiixmcuin.linkpc.net/9200200204203200/The-Girl-Who-Saved-Christmas-A-Boy-Called-Christmas-Father-Christmas-and-Me-by-Matt-Haig.pdf
    • http://xiixmcuin.linkpc.net/8207204200204209/Kla-Judrikis-No-Ohsolakalna-Pee-Deewaatsihschanas-Nahze-by-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/5202200205205209/A-Curious-Bundle-for-Bo-Bo-and-Cha-Cha-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-