Malicious PDF — malware analysis report

Static analysis result for SHA-256 d48fdd76a6e63d8c…

MALICIOUS

PDF

14.1 KB Created: 2019-04-30 02:54:09 +01:00 Authoring application: mPDF 5.7
MD5: 78f5e1ad242b2910d13bc89c58cba2bd SHA-1: 84c0096a25699523c82118e6751a65d4bfe3e22f SHA-256: d48fdd76a6e63d8c1c5c79d62f68a162463f978965e1ff323037053a1e29d7ff
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various PDF documents, likely as part of a link farm or SEO poisoning scheme. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to manipulate search results or distribute further content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7208209202206208/Poetry-by-Sylvia-Plath-Ariel-Ennui-Daddy-Lady-Lazarus-Two-Lovers-and-a-Beachcomber-by-the-Real-Sea-the-Munich-Mannequins-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/7204208206201200/Letters-of-Sylvia-Plath-Volume-1-1940-1956-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/4208203206202207/Sylvia-Plath-Reads-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/3201203208203200/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/2205201200204200/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/3200201207207200/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/8200207200203/Ariel-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/3201207202209209/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/9202207201203202/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/5205203206204205/The-Bell-Jar-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/9200207207200/Letters-Home-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/1205209200201206/Her-Husband-Ted-Hughes-and-Sylvia-Plath---A-Marriage-by-Diane-Wood-Middlebrook.pdf
    • http://xiixmcuin.linkpc.net/4207207205204203/Mad-Girl-s-Love-Song-Sylvia-Plath-and-Life-Before-Ted-by-Andrew-Wilson.pdf
    • http://xiixmcuin.linkpc.net/6208206206202209/Ariel-s-Gift-Ted-Hughes-Sylvia-Plath-and-the-Story-of-Birthday-Letters-by-Erica-Wagner.pdf
    • http://xiixmcuin.linkpc.net/1206208206200206/Pain-Parties-Work-Sylvia-Plath-in-New-York-Summer-1953-by-Elizabeth-Winder.pdf
    • http://xiixmcuin.linkpc.net/3202206203203206/Johnny-Panic-and-the-Bible-of-Dreams-Short-Stories-Prose-and-Diary-Excerpts-by-Sylvia-Plath.pdf
    • http://xiixmcuin.linkpc.net/8202202205200/Collected-Poems-by-W-H-Auden.pdf
    • http://xiixmcuin.linkpc.net/2203206203207/Collected-Poems-by-Josephine-Miles.pdf
    • http://xiixmcuin.linkpc.net/2201208208208/New-and-Collected-Poems-by-Richard-Wilbur.pdf
    • http://xiixmcuin.linkpc.net/1203209207203200/Collected-Poems-by-Geoffrey-Hill.pdf
    • http://xiixmcuin.linkpc.net/120520920020