Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d4e206e2ee3d8f…

MALICIOUS

PDF

14.3 KB Created: 2019-05-01 17:32:15 +01:00 Authoring application: mPDF 5.7
MD5: 5213d507f9184b99cd8d1578675cbc89 SHA-1: 7d48eae34d87f0d462ae9277e7aa1b76d5ff9019 SHA-256: d9d4e206e2ee3d8fb3bb58d1eda78e955ebf54362fc3616dd4a3ae4e3ed1b0ed
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely intended to deceive users into clicking them, potentially leading to malicious content. The URLs themselves point to PDF files with numeric slugs, suggesting an attempt to appear as legitimate book downloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201201207204206204/Clinical-Interviewing-by-John-Sommers-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1208200209209202/The-Ghostfaces-Brotherband-6-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/5208205205206203/De-koning-van-Clonmel-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3207206204208/The-Invaders-Brotherband-Chronicles-2-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/8204202205203/Ho-c-most-Hrani-v-u-e-2-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1202205208203208/Flanagan-and-the-Crown-of-Mexico-by-John-Reisinger.pdf
    • http://xiixmcuin.linkpc.net/4201201200201205/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/8206203203202200/Die-Legenden-des-K-nigreichs-Die-Chroniken-von-Araluen-11-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3201206200200204/The-Sorcerer-of-the-North-Ranger-s-Apprentice-5-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1208200209203208/Ranger-s-Apprentice-2-The-Burning-Bridge-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/5204205205201201/Freres-D-Armes-Feuilleton-Brotherband-1-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/2205206204200201/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/7206209205205/The-Kings-of-Clonmel-Ranger-s-Apprentice-8-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1208201201207206/The-Sorcerer-in-the-North-Ranger-s-Apprentice-5-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3203207200205/The-Sorcerer-in-the-North-Ranger-s-Apprentice-5-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3203201202204203/The-Battle-for-Skandia-Ranger-s-Apprentice-4-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/2209208207204208/Oakleaf-Bearers-Ranger-s-Apprentice-4-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/3203209208200/Erak-s-Ransom-Ranger-s-Apprentice-7-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/8200206205209/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1208201200204205/Halt-s-Peril-Ranger-s-Apprentice-9-by-John-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/2205206204200201/The-Ruins-of-Gorlan-Ranger-s-Apprentic