Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1e7389382499c26…

MALICIOUS

PDF

20.3 KB Created: 2019-04-30 01:45:45 +01:00 Authoring application: mPDF 5.7
MD5: 4281279836324a08f627cd6836daaaae SHA-1: 79cb6b04150667c1746fac76d138531835e4754a SHA-256: d1e7389382499c264eac4fead0889a90dcfe233c6f65216ed1d436c4855f92ca
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the same domain, suggesting a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic indicate a potentially malicious intent to redirect users or manipulate search engine results. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2206206209205200/Dark-Alchemy-Magical-Tales-From-Masters-Of-Modern-Fantasy-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/2206200209204/Wizards-Magical-Tales-From-the-Masters-of-Modern-Fantasy-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/2200203207204208/The-Golden-Horse-amp-Other-Fairy-Tales-Modern-Fairy-Tales-for-the-Magical-Child-by-StarFields.pdf
    • http://xiixmcuin.linkpc.net/4202201202200201/Dark-Duets-All-New-Tales-of-Horror-and-Dark-Fantasy-by-Christopher-Golden.pdf
    • http://xiixmcuin.linkpc.net/1206204202207206/Tales-Before-Tolkien-The-Roots-of-Modern-Fantasy-by-Douglas-A-Anderson.pdf
    • http://xiixmcuin.linkpc.net/3201203206202208/The-Mammoth-Book-of-Sorcerers-Tales-The-Ultimate-Collection-of-Magical-Fantasy-from-Tom-Holt-Ursula-K-LeGuin-Michael-Moorcock-Peter-Crowther-Louise-Cooper-and-many-more-by-Mike-Ashley.pdf
    • http://xiixmcuin.linkpc.net/4204204205207207/Jack-O--Spec-Tales-of-Halloween-and-Fantasy-by-Karen-A-Romanko.pdf
    • http://xiixmcuin.linkpc.net/3208207209209/Poe-19-New-Tales-of-Suspense-Dark-Fantasy-and-Horror-Inspired-by-Edgar-Allan-Poe-by-Ellen-Datlow.pdf
    • http://xiixmcuin.linkpc.net/4203208208204201/The-Outspoken-Princess-and-The-Gentle-Knight-A-Treasury-of-Modern-Fairy-Tales-by-Jack-D-Zipes.pdf
    • http://xiixmcuin.linkpc.net/7206202204205201/Dark-Tales-Beauty-and-the-Beast-A-Modern-Retelling-by-Gabrielle-Suzanne-Barbot-de-Villeneuve.pdf
    • http://xiixmcuin.linkpc.net/3204203208205205/Giants-Magical-Worlds-of-Fantasy-5-by-Isaac-Asimov.pdf
    • http://xiixmcuin.linkpc.net/2209205204202208/Dragons-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/8208200204207204/Dinosaurs-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/8208200204202208/Unicorns-2-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/8208200204202207/Nanotech-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/8208200204206209/Futures-Past-by-Jack-Dann.pdf
    • http://xiixmcuin.linkpc.net/6206203204206201/Scale-of-Mermaid-Magical-Ingredients-Fantasy-Journal-4-by-Angel-Leya.pdf
    • http://xiixmcuin.linkpc.net/6206203204205207/Wing-of-Fairy-Magical-Ingredients-Fantasy-Journal-3-by-Angel-Leya.pdf
    • http://xiixmcuin.linkpc.net/2203207201209202/Bota-E-Fantazise-The-World-Of-Fantasy-Chapter-02---Where-Are-You-Magical-Bird-by-Stela-Canga.pdf
    • http://xiixmcuin.linkpc.net/1200209209207209206/The-Hashemites-in-the-Modern-Arab-World-Essays-in-Honour-of-the-Late-Professor-Uriel-Dann-by-Asher-Susser.pdf
    • http://xiixmcuin.linkpc.net/3201203206202208/The-Mammoth-Book-of-Sorcerers-Tales-The-Ultimate-Collection-of-Magical-Fantasy-from-Tom-Holt-Ursula-K-LeGuin