Malicious PDF — malware analysis report

Static analysis result for SHA-256 c41eef312264fa42…

MALICIOUS

PDF

20.7 KB Created: 2019-05-06 23:33:15 +01:00 Authoring application: mPDF 5.7
MD5: 5310978aa233912eb4a90ba39c2f549c SHA-1: b166c8353e19ced34b32db45ac72cafb1967fda4 SHA-256: c41eef312264fa429a5dcd3dc08d7cd8cdb66addb39624292bd73ef82a5d7a5b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on the domain 'xiixmcuin.linkpc.net'. This pattern is indicative of a link farm or a content-spinning operation designed to attract traffic or potentially distribute malicious content. While the URLs themselves are currently marked as benign, the sheer volume and the use of a dynamic DNS hostname suggest a malicious intent to obscure the true nature of the hosted content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201205207206207204/Lachen-op-Plattd-tsch---Lachen-auf-Plattdeutsch-by-Ludwig-Frahm.pdf
    • http://xiixmcuin.linkpc.net/8201202201200/Thorn-Rosa-Thorn-Thriller-1-by-Vena-Cork.pdf
    • http://xiixmcuin.linkpc.net/4208208209206209/Papa-s-Daughter-The-Franzons-2-by-Thyra-Ferr-Bj-rn.pdf
    • http://xiixmcuin.linkpc.net/3204200207206207/Simon-Thorn-and-the-Wolf-s-Den-Simon-Thorn-1-by-Aimee-Carter.pdf
    • http://xiixmcuin.linkpc.net/1201205209205205206/Schweine-halten-by-Beate-Peitz.pdf
    • http://xiixmcuin.linkpc.net/1201207209200205202/Das-Schweigen-der-Schweine-by-Alexa-Rudolph.pdf
    • http://xiixmcuin.linkpc.net/8209200205202205/Perverse-Schweine-Festa-Extrem-by-Matt-Shaw.pdf
    • http://xiixmcuin.linkpc.net/1201207209200205206/A-House-For-Pigs-And-People-Ein-Haus-F-r-Schweine-Und-Menschen-by-Carsten-H-ller.pdf
    • http://xiixmcuin.linkpc.net/1201207209200205209/Bullen-und-Schweine-Kommissar-Wolf-rettet-die-Welt-by-Josef-Kelnberger.pdf
    • http://xiixmcuin.linkpc.net/1200203204207208201/Knallerbsen-oder-Du-sollst-und-mu-t-lachen-by-Fr-Rabener.pdf
    • http://xiixmcuin.linkpc.net/1201205207208208206/Die-werden-lachen-in-Teplitz-Sch-nau-by-Anna-Lindner.pdf
    • http://xiixmcuin.linkpc.net/1201205207202207207/Heimatkinder-2---Heimatroman-Als-Vreneli-wieder-lachen-lernte-by-Ute-Amber.pdf
    • http://xiixmcuin.linkpc.net/9203207202202203/Sternstunden-des-Humors-Wor-ber-die-sterreicher-lachen-by-Felix-Dvorak.pdf
    • http://xiixmcuin.linkpc.net/9203207202202204/Saunagefl-ster-Wor-ber-Frauen-tuscheln-lachen-l-stern-by-Gabriele-Hefele.pdf
    • http://xiixmcuin.linkpc.net/1201204203205205207/Vorbild-Und-Vernunft-Die-Regelung-Von-Lachen-Und-Scherzen-Im-Mittelalterlichen-Islam-by-Ludwig-Ammann.pdf
    • http://xiixmcuin.linkpc.net/5204202206200207/Seliges-Lacheln-Und-Hollisches-Gelachter-Das-Lachen-in-Kunst-Und-Kultur-Des-Mittelalters-by-Winfried-Wilhelmy.pdf
    • http://xiixmcuin.linkpc.net/1201205207205202203/Mitunter-Sogar-Lachen-E-Held-D-Westl-Welt-Uber-D-Zerstorerischen-Grundlagen-Unserer-Zivilisation-by-Horst-Kurnitzky.pdf
    • http://xiixmcuin.linkpc.net/1201207209201202209/Populares-Handbuch-Der-Landwirthschaft-Fur-Den-Praktischen-Landwirth-Nach-Dem-Gegenwartigen-Standpunkte-Der-Fortschritte-Im-Acker--Wiesen--Und-Weinbau-in-Der-Obstbaumzucht-Der-Rindvieh--Schaf--Pferde--Schweine--Und-Bienenzucht-Eine-Gekronte-by-J-a-Schlipf.pdf
    • http://xiixmcuin.linkpc.net/1200208207208206/Thorn-by-Intisar-Khanani.pdf
    • http://xiixmcuin.linkpc.net/1200207208203208/War-Boy-by-Thorn-Kief-Hillsbery.pdf
    • http://xiixmcuin.linkpc.net/1200203204207208201/Knall