Malicious PDF — malware analysis report

Static analysis result for SHA-256 c84e3164031a4524…

MALICIOUS

PDF

16.3 KB Created: 2019-05-01 19:44:10 +01:00 Authoring application: mPDF 5.7
MD5: 5f601246f26e53458ee53d2c338ec6c8 SHA-1: 36e63d5b373c7c3f522ba4e9087a3353c3c6d07c SHA-256: c84e3164031a45242fbf0e07166178784adf9717606867ffa1b9f9e0708b1bb0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a distribution point for further malicious content. While the specific intent beyond linking is unclear due to the nature of the PDF content, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious purpose, likely to drive traffic or distribute other malicious files. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/9202201209203203/20-000-Leagues-Under-the-Sea-1000-Copy-Limited-Edition-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/9202201209209207/Journey-to-the-Center-of-the-Earth-1000-Copy-Limited-Illustrated-Edition-SF-Classic-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/9202201209202208/The-War-of-the-Worlds-1000-Copy-Limited-Edition-by-H-G-Wells.pdf
    • http://xiixmcuin.linkpc.net/9202201209203207/The-Age-of-Innocence-1000-Copy-Limited-Edition-by-Edith-Wharton.pdf
    • http://xiixmcuin.linkpc.net/9202201208203206/The-Metamorphosis-1000-Copy-Limited-Edition-by-Franz-Kafka.pdf
    • http://xiixmcuin.linkpc.net/9202202200200208/The-Jungle-Book-1000-Copy-Limited-Edition-by-Rudyard-Kipling.pdf
    • http://xiixmcuin.linkpc.net/9202202200205204/A-Princess-of-Mars-1000-Copy-Limited-Edition-by-Edgar-Rice-Burroughs.pdf
    • http://xiixmcuin.linkpc.net/9202202200201201/Swann-s-Way-In-Search-of-Lost-Time-1000-Copy-Limited-Edition-by-Marcel-Proust.pdf
    • http://xiixmcuin.linkpc.net/9202202200205208/The-Legend-of-Sleepy-Hollow-and-Other-Stories-1000-Copy-Limited-Edition-Or-the-Sketch-Book-of-Geoffrey-Crayon-Gent-by-Washington-Irving.pdf
    • http://xiixmcuin.linkpc.net/5205201201201209/Twenty-Thousand-Leagues-Under-The-Sea-By-Jules-Verne-Illustrated-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/8206206201204207/20-000-Leagues-Under-The-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/5203201203201203/20-000-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/1200201208202204206/20-000-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/6209209202201205/20-000-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/9206202201204207/20-000-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/3202200200201205/20000-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/7200207206202/Twenty-Thousand-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/4208201202204209/Twenty-Thousand-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/1200203206202201200/Twenty-Thousand-Leagues-Under-the-Sea-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/1200204201208209208/20-000-Leagues-Under-the-Sea-Includes-eBook-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/9202202200205208/The-Legend-of-Sleepy-Hollow-and-Other-Stories-1000-Copy-Limited-Edition-Or-the-Sketch-Book-of-Geoffrey-Crayon-Gent-by-W