Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0e933fbd885bcef…

MALICIOUS

PDF

15.8 KB Created: 2019-05-01 17:11:45 +01:00 Authoring application: mPDF 5.7
MD5: 81eb8d8663d48b97d07240eb757b9ef8 SHA-1: 847364bd0f9de8d03008bf610221daddd89dfa27 SHA-256: c0e933fbd885bcef358456c80de7f29fbb0cf35251de6e412cd23982db340551
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on the same domain, xiixmcuin.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and nature of these links suggest a potential SEO manipulation or content distribution scheme, which is a common tactic for distributing malicious payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6202209207207200/Perfection-2-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/6202209207207202/Perfection-3-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/7203201202205202/Slammed-3-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/9205200207209208/Priest-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/1200204201206200204/Naughty-Professor-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/3203209209207/Twisted-Perfection-Rosemary-Beach-5-Perfection-1-by-Abbi-Glines.pdf
    • http://xiixmcuin.linkpc.net/4200203200209/Simple-Perfection-Rosemary-Beach-6-Perfection-2-by-Abbi-Glines.pdf
    • http://xiixmcuin.linkpc.net/8205205206209204/Fighting-Seduction-The-Boss-1-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/4205209204203202/Shattered-Perfection-The-Perfection-Series-1-by-Heather-Guimond.pdf
    • http://xiixmcuin.linkpc.net/4200205205200200/Wired-For-the-Billionaire-s-Pleasure-Luke-amp-Claire-1-by-Evelyn-Adams.pdf
    • http://xiixmcuin.linkpc.net/1202206205205201/Perfection-Perfection-1-by-Merphy-Napier.pdf
    • http://xiixmcuin.linkpc.net/3206207205200208/Stepbrother-Wow-Stepbrother-1-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/7203201202204200/Slammed-1-Slammed-1-by-Claire-Adams.pdf
    • http://xiixmcuin.linkpc.net/3209204201204202/Chasing-Perfection-Vol-III-Chasing-Perfection-3-by-M-S-Parker.pdf
    • http://xiixmcuin.linkpc.net/9203200201201202/Hallo-Claire---I-miss-you-Marie-amp-Claire-1-by-Renate-Ahrens.pdf
    • http://xiixmcuin.linkpc.net/1201203204203209206/Ploughshares-Summer-2016-Guest-Edited-by-Claire-Messud-amp-James-Wood-by-Claire-Messud.pdf
    • http://xiixmcuin.linkpc.net/1208202208203209/The-Book-of-Abigail-and-John-Selected-Letters-of-the-Adams-Family-1762-1784-by-Abigail-Adams.pdf
    • http://xiixmcuin.linkpc.net/5208206208204205/Democracy-Esther-Mont-Saint-Michel-and-Chartres-The-Education-of-Henry-Adams-by-Henry-Adams.pdf
    • http://xiixmcuin.linkpc.net/1208202201209/Claire-Murray-Nantucket-Inspirations-Designs-Charts-amp-Folklore-by-Claire-Murray.pdf
    • http://xiixmcuin.linkpc.net/7203203205205203/In-the-Hands-of-A-Chef-Cooking-with-Jody-Adams-of-Rialto-Restaurant-by-Jody-Adams.pdf
    • http://xiixmcuin.linkpc.net/3206207205200208/Stepbrothe