Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc2103535d74f5b0…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 03:31:29 +01:00 Authoring application: mPDF 5.7
MD5: 79f8ba06ff7388580bd3e95554735095 SHA-1: 1723128f79646f1b07198e317fca23f711a7686c SHA-256: bc2103535d74f5b08c36d54228efcfec3fa8d8d6fa40e7ded937e87a12004364
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the presence of a ClamAV detection (Pdf.Dropper.Agent-7162362-0) suggest a malicious intent, possibly to distribute further malware or engage in SEO-based phishing. The embedded URLs are the primary IOCs.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7162362-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7162362-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3205206203206202/The-Rainey-Season-Rainey-Bell-3-by-R-E-Bradshaw.pdf
    • http://xiixmcuin.linkpc.net/3205206205207209/Rainey-s-Christmas-Miracle-Rainey-Bell-2-5-by-R-E-Bradshaw.pdf
    • http://xiixmcuin.linkpc.net/1209205202203/Rainey-Nights-Rainey-Bell-2-by-R-E-Bradshaw.pdf
    • http://xiixmcuin.linkpc.net/8209206204202/Rainey-Days-Rainey-Bell-1-by-R-E-Bradshaw.pdf
    • http://xiixmcuin.linkpc.net/2209205208205207/What-She-Wants-Cape-May-1-by-Anne-Rainey.pdf
    • http://xiixmcuin.linkpc.net/7207203205206206/Preparing-for-Marriage-by-Dennis-Rainey.pdf
    • http://xiixmcuin.linkpc.net/7205208200201/Toni-s-Blues-by-Jacqueline-Rainey.pdf
    • http://xiixmcuin.linkpc.net/1208202209206200/These-Hellish-Happenings-by-Jennifer-Rainey.pdf
    • http://xiixmcuin.linkpc.net/4203201205200204/Ride-of-Her-Life-by-Anne-Rainey.pdf
    • http://xiixmcuin.linkpc.net/3201202200202208/Secret-Hiding-Place-by-Rainey-Bennett.pdf
    • http://xiixmcuin.linkpc.net/6202207206204206/Crosshairs-A-Rainey-amp-Levine-Thriller-2-by-J-A-Schneider.pdf
    • http://xiixmcuin.linkpc.net/4202205209203202/Pleasure-Bound-Hard-to-Get-2-by-Anne-Rainey.pdf
    • http://xiixmcuin.linkpc.net/4200200209202208/The-Gaki-and-Other-Hungry-Spirits-by-Stephen-Mark-Rainey.pdf
    • http://xiixmcuin.linkpc.net/1200201208207205/Ministering-to-Twenty-First-Century-Families-by-Dennis-Rainey.pdf
    • http://xiixmcuin.linkpc.net/2208201202205205/Swag-Southern-Women-Aging-Gracefully-by-Melinda-Rainey-Thompson.pdf
    • http://xiixmcuin.linkpc.net/2201205202207206/Blues-Legacies-and-Black-Feminism-Gertrude-quot-Ma-quot-Rainey-Bessie-Smith-and-Billie-Holiday-by-Angela-Y-Davis.pdf
    • http://xiixmcuin.linkpc.net/6205203202206206/--season-II-14-Rozario-to-Banpaia-Season-II-14-Rosario-Vampire-Season-II-14-by-Akihisa-Ikeda.pdf
    • http://xiixmcuin.linkpc.net/1205206208207/Bell-Alexander-Graham-Bell-and-the-Conquest-of-Solitude-by-Robert-V-Bruce.pdf
    • http://xiixmcuin.linkpc.net/4203208200209200/Seven-Crows-Buffy-the-Vampire-Slayer-Season-7-8-1-Angel-Season-4-5-1-by-John-Vornholt.pdf
    • http://xiixmcuin.linkpc.net/4203208200209205/Heat-Buffy-the-Vampire-Slayer-Season-7-8-5-Angel-Season-4-5-3-by-Nancy-Holder.pdf
    • http://xiixmcuin.linkpc.net/6202207206204206/Crosshairs-A-Raine