Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf364db023f82fe0…

MALICIOUS

PDF

21.6 KB Created: 2019-05-02 19:14:47 +01:00 Authoring application: mPDF 5.7
MD5: 5026af6dfda61823cf32ee0dad4ef6c5 SHA-1: ae6af7641d86cef9523743fd8c76a91f00d101f2 SHA-256: cf364db023f82fe0ec624cdeeeecbcc28835b494088d2e14b092fa32f7ec45a2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the `xiixmcuin.linkpc.net` domain. This heuristic firing suggests a link farm or a method to distribute further content. The document body, though heavily obfuscated, contains URLs that are consistent with the link farm heuristic. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1209201204205205/The-Magic-of-Thinking-Big-by-David-J-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/1201205201201208/The-Day-the-Rabbi-Disappeared-Jewish-Holiday-Tales-of-Magic-by-Howard-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/2206205202202202/The-Thinking-Woman-s-Guide-to-Real-Magic-by-Emily-Croy-Barker.pdf
    • http://xiixmcuin.linkpc.net/1200203205208/The-Thinking-Woman-s-Guide-to-Real-Magic-by-Emily-Croy-Barker.pdf
    • http://xiixmcuin.linkpc.net/2207203209206/Superpowers-by-David-J-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/1200208202200204/If-Dogs-Were-Dinosaurs-by-David-M-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/5205205200203208/Magia-de-pensar-en-grande-La-by-David-J-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/3203201201200201/G-Is-for-Googol-A-Math-Alphabet-Book-by-David-M-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/8202200203203204/The-Last-Man-Who-Knew-Everything-The-Life-and-Times-of-Enrico-Fermi-Father-of-the-Nuclear-Age-by-David-N-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/8201208201203201/Torts-Cases-and-Materials-10th-Edition-Prosser-Wade-and-Schwartz-University-Casebook-by-Victor-E-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/6205205209208204/Magic-Kingdom---Foreclosed-A-Spoof-Based-on-Terry-Brooks-Magic-Kingdom-for-Sale-From-the-Author-of-the-Frontmire-Histories-by-David-E-Daigle.pdf
    • http://xiixmcuin.linkpc.net/7208202201202205/Sumo-A-Thinking-Fan-s-Guide-to-Japan-s-National-Sport-by-David-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/5204209200203208/David-Copperfield-Illustrated-with-Critical-Thinking-Discussion-Questions-by-Charles-Dickens.pdf
    • http://xiixmcuin.linkpc.net/4204201208202202/Talking-Back-Thinking-Feminist-Thinking-Black-by-bell-hooks.pdf
    • http://xiixmcuin.linkpc.net/4209202206200202/Contagious-Optimism-Uplifting-Stories-and-Motivational-Advice-for-Positive-Forward-Thinking-by-David-Mezzapelle.pdf
    • http://xiixmcuin.linkpc.net/3203205203202/Blink-The-Power-of-Thinking-Without-Thinking-by-Malcolm-Gladwell.pdf
    • http://xiixmcuin.linkpc.net/2208204201208206/Remove-Negative-Thinking-How-to-Instantly-Harness-Mindfulness-and-The-Power-of-Positive-Thinking-The-GirlBizMind-Series-Book-1-by-Helga-Klopcic.pdf
    • http://xiixmcuin.linkpc.net/1205208204201206/The-Magic-Goes-Away-Collection-The-Magic-Goes-Away-The-Magic-May-Return-More-Magic-by-Larry-Niven.pdf
    • http://xiixmcuin.linkpc.net/9203203209206208/The-Power-of-Positive-Thinking-and-the-Amazing-Results-of-Positive-Thinking-Collection-by-Norman-Vincent-Peale.pdf
    • http://xiixmcuin.linkpc.net/7200200209200202/Secrets-of-My-Magic-by-David-Devant.pdf
    • http://xiixmcuin.linkpc.net/8201208201203201/Torts-Cases-and-Materials-10th-Edition-Pross