Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4879c662e00be77…

MALICIOUS

PDF

22.9 KB Created: 2019-05-02 18:37:29 +01:00 Authoring application: mPDF 5.7
MD5: ffc2abbdb2db68d537652c2d89861bd6 SHA-1: 0609fb9c2e684c68c2e1df0c57e7a5d731aac463 SHA-256: d4879c662e00be779793ffd8833173dc00eba550118ff9f518ec21df67d83a18
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF documents. These URLs are presented in a way that suggests a link farm, likely intended to deceive users into clicking them. The document body contains these URLs, reinforcing the attack pattern. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2203202203208208/A-History-of-Britain-The-Key-Events-That-Have-Shaped-Britain-from-Neolithic-Times-to-the-21st-Century-by-Richard-Dargie.pdf
    • http://xiixmcuin.linkpc.net/3208203203205200/A-History-of-Britain-The-Wars-of-the-British-1603-1776-A-History-of-Britain-2-by-Simon-Schama.pdf
    • http://xiixmcuin.linkpc.net/8206206202209203/A-History-of-Britain-At-the-Edge-of-the-World-3000-BC---AD-1603-A-History-of-Britain-1-by-Simon-Schama.pdf
    • http://xiixmcuin.linkpc.net/3204200207204206/Phoenix-The-History-of-the-Countryside-The-Classic-History-of-Britain-s-Landscape-Flora-and-Fauna-by-Oliver-Rackham.pdf
    • http://xiixmcuin.linkpc.net/5200209203204203/ICL-A-Business-and-Technical-History-The-Official-History-of-Britain-s-Leading-Information-Systems-Company-by-Martin-Campbell-Kelly.pdf
    • http://xiixmcuin.linkpc.net/4200201206202202/A-Very-Brief-History-of-Britain-by-Alasdair-C-Shaw.pdf
    • http://xiixmcuin.linkpc.net/1209204204209200/Haunted-Inns-of-Britain-and-Ireland-by-Richard-Jones.pdf
    • http://xiixmcuin.linkpc.net/1201205200209206205/Legendary-Golf-Clubhouses-of-the-U-S-and-Great-Britain-by-Richard-Diedrich.pdf
    • http://xiixmcuin.linkpc.net/3201201204203200/The-History-of-the-Kings-of-Britain-by-Geoffrey-of-Monmouth.pdf
    • http://xiixmcuin.linkpc.net/5200209203204208/Lead-Manufacturing-in-Britain-A-History-by-D-J-Rowe.pdf
    • http://xiixmcuin.linkpc.net/9203201205205203/Caught-in-the-Machinery-Workplace-Accidents-and-Injured-Workers-in-Nineteenth-Century-Britain-by-Jamie-Bronstein.pdf
    • http://xiixmcuin.linkpc.net/9203203208207206/The-Bible-in-History-How-the-Texts-Have-Shaped-the-Times-by-David-W-Kling.pdf
    • http://xiixmcuin.linkpc.net/1204202207205201/Never-Had-It-So-Good-A-History-of-Britain-from-Suez-to-the-Beatles-by-Dominic-Sandbrook.pdf
    • http://xiixmcuin.linkpc.net/8204201208207207/Execution-A-History-of-Capital-Punishment-in-Britain-by-Simon-Webb.pdf
    • http://xiixmcuin.linkpc.net/4200203200206204/From-Blitz-to-Blair-A-New-History-of-Britain-Since-1939-by-Nick-Tiratsoo.pdf
    • http://xiixmcuin.linkpc.net/5200209203202207/The-Official-History-of-Britain-and-the-Channel-Tunnel-Government-Official-History-Series-by-Terry-Gourvish.pdf
    • http://xiixmcuin.linkpc.net/7203208203206203/Rethinking-Orphanages-for-the-21st-Century-by-Richard-B-McKenzie.pdf
    • http://xiixmcuin.linkpc.net/2207209208209205/Murder-at-the-Inn-A-Criminal-History-of-Britain-s-Pubs-and-Hotels-by-James-Moore.pdf
    • http://xiixmcuin.linkpc.net/2205206209205204/The-Most-Dangerous-Enemy-The-Definitive-History-of-the-Battle-of-Britain-by-Stephen-Bungay.pdf
    • http://xiixmcuin.linkpc.net/4202202209205200/Never-Had-It-So-Good-A-History-of-Britain-from-Suez-to-the-Beatles-1956-63-by-Dominic-Sandbrook.pdf
    • http://xiixmcuin.linkpc.net/3204200207204206/Phoenix-The-History-of-the-Countrysid