Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4eb199816215478…

MALICIOUS

PDF

16.4 KB Created: 2019-04-07 12:37:54 +01:00 Authoring application: mPDF 5.7
MD5: 7726a65220d2afadf4b26e39d78f0184 SHA-1: dae1ffc993499971439f5c3ac769c090f30ed1ff SHA-256: d4eb199816215478d08856f331b91fa1befb6d728e7a38c44d077b167b5d9565
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting a malicious intent to direct users to potentially harmful content. The document body is heavily obfuscated and unreadable, but the presence of numerous links to external PDFs is the main indicator of malicious activity. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201202205207207200/That-s-When-Buzz-Met-Bee-by-Elaine-Kleid.pdf
    • http://xiixmcuin.linkpc.net/1201202205207207206/Top-10-Reasons-Why-Suicide-Is-Not-The-Answer-by-Elaine-Kleid.pdf
    • http://xiixmcuin.linkpc.net/1201202205207206202/The-Sad-Truth-About-Elderly-Abuse-by-Elaine-Kleid.pdf
    • http://xiixmcuin.linkpc.net/1201202205207207202/Irate-Customers-No-Problem-by-Elaine-Kleid.pdf
    • http://xiixmcuin.linkpc.net/1201202205207206207/Change-Your-Words-Change-Your-Thoughts-Change-Your-Life-by-Elaine-Kleid.pdf
    • http://xiixmcuin.linkpc.net/4202205204201204/Santa-Is-Coming-to-New-York-by-Steve-Smallman.pdf
    • http://xiixmcuin.linkpc.net/3207204206203205/Santa-Claus-is-Coming-Harlequin-Intrigue-254-by-M-J-Rodgers.pdf
    • http://xiixmcuin.linkpc.net/4202200208209209/The-House-by-the-Sea-by-Santa-Montefiore.pdf
    • http://xiixmcuin.linkpc.net/5200201205209203/Who-Is-Coming-to-Our-House-by-Joseph-Slate.pdf
    • http://xiixmcuin.linkpc.net/3207205209206203/Strangers-in-the-House-Coming-of-Age-in-Occupied-Palestine-by-Raja-Shehadeh.pdf
    • http://xiixmcuin.linkpc.net/1202203205202203/F-Bomb-A-Story-About-Coming-Out-and-Coming-Out-of-One-s-Shell-by-Naomi-Rabinowitz.pdf
    • http://xiixmcuin.linkpc.net/4201206202202204/Santa-s-Favorite-Story-Santa-Tells-the-Story-of-the-First-Christmas-by-Hisako-Aoki.pdf
    • http://xiixmcuin.linkpc.net/1205203201204203/My-Red-Blood-A-Memoir-of-Growing-Up-Communist-Coming-Onto-the-Greenwich-Village-Folk-Scene-and-Coming-Out-in-the-Feminist-Movement-by-Alix-Dobkin.pdf
    • http://xiixmcuin.linkpc.net/1201202205207201202/Last-Dance-by-Neil-Kleid.pdf
    • http://xiixmcuin.linkpc.net/1201202205205203203/Brownsville-by-Neil-Kleid.pdf
    • http://xiixmcuin.linkpc.net/2204201208204204/Santa-Paws-Come-Home-Santa-Paws-3-by-Nicholas-Edwards.pdf
    • http://xiixmcuin.linkpc.net/1201202205207201206/Die-Frau-im-gepunkteten-Kleid-Roman-by-Beryl-Bainbridge.pdf
    • http://xiixmcuin.linkpc.net/1201202205207202202/Das-Geoffnete-Kleid-Von-Giorgione-Zu-Tiepolo-by-Verena-Auffermann.pdf
    • http://xiixmcuin.linkpc.net/1201202205205203202/The-Call-of-the-Wild-Graphic-Novels-by-Neil-Kleid.pdf
    • http://xiixmcuin.linkpc.net/3205204208206209/Santa-Olivia-Santa-Olivia-1-by-Jacqueline-Carey.pdf