Malicious PDF — malware analysis report

Static analysis result for SHA-256 db0640e8d9f719b0…

MALICIOUS

PDF

20.7 KB Created: 2019-05-04 10:42:32 +01:00 Authoring application: mPDF 5.7
MD5: 735e46837618d3602c001f99f2e465ab SHA-1: 400c8343ff5caea30e3079121a323daa69338fb8 SHA-256: db0640e8d9f719b0c2fdc3f45a5f4669de91137836fb269dacbc916c278d4834
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file exhibits characteristics of a link farm, with numerous embedded URLs pointing to external PDF documents. The heuristic 'PDF_SEO_LINK_FARM' indicates a high volume of these links, suggesting an attempt to manipulate search engine results or distribute content through a large number of seemingly unrelated documents. While no scripts were extracted, the sheer volume of links and their distribution across various domains points to a coordinated effort for SEO manipulation or traffic redirection. The IOCs are the primary URLs identified in the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200203202208201200/Sieben-Sekunden-Sch-pfung-by-Max-Mann.pdf
    • http://xiixmcuin.linkpc.net/1200203203201203202/Sieben-Sekunden-Sch-pfung---Teil-1-by-Max-Mann.pdf
    • http://xiixmcuin.linkpc.net/1201204200204201208/Mein-Mann-meine-Schwiegermutter-und-ich-Ein-Mann-zwischen-zwei-Frauen-by-Dorothee-D-ring.pdf
    • http://xiixmcuin.linkpc.net/3206201200203202/Dead-Mann-Running-Hessius-Mann-2-by-Stefan-Petrucha.pdf
    • http://xiixmcuin.linkpc.net/1201200206200203205/Traumprinz-gesucht-wie-Mann-an-den-Mann-kommt-by-Rolf-Winiarski.pdf
    • http://xiixmcuin.linkpc.net/1201204204202200204/Sprachgebrauch-Und-Sprachsch-pfung-in-Wieland-s-Prosaischen-Hauptwerken-N-mlich-Don-Sylvio-Di-Rosalva-Agathon-Der-Goldne-Spiegel-Geschichte-Des-Weisen-Danischmend-Geschichte-Der-Abderiten-Peregnius-Proteus-Aristipp-Ein-Beitrag-Zur-Deutschen-Le-by-Louis-Lubovius.pdf
    • http://xiixmcuin.linkpc.net/1200203202208200208/Italienisch-in-60-Sekunden-by-Holger-Davidoff.pdf
    • http://xiixmcuin.linkpc.net/1200203202209208209/Wein-in-30-Sekunden-by-Gerard-Basset-OBE.pdf
    • http://xiixmcuin.linkpc.net/1200203202209207209/Mathe-in-30-Sekunden-by-Richard-Brown.pdf
    • http://xiixmcuin.linkpc.net/1201201200207208200/Ausgew-hlte-Werke-Jeder-stirbt-f-r-sich-allein-Der-junge-Goedeschal-Bauern-Bonzen-und-Bomben-Kleiner-Mann-was-nun-M-rchen-vom-Stadtschreiber-Wolf-Ein-Mann-will-nach-oben-by-Hans-Fallada.pdf
    • http://xiixmcuin.linkpc.net/1200203202207209209/Spielkarten-merken-in-Sekunden-by-Michael-Lutz.pdf
    • http://xiixmcuin.linkpc.net/1200203202208201204/Darm-in-60-Sekunden-erkl-rt-by-Kerstin-Menzel.pdf
    • http://xiixmcuin.linkpc.net/1200203202209207208/Gefl-gelte-Worte-in-5-Sekunden-by-Matteo-Civaschi.pdf
    • http://xiixmcuin.linkpc.net/1200203203202201209/Besser-f-hlen-in-17-Sekunden-by-Karin-Jaquet.pdf
    • http://xiixmcuin.linkpc.net/1200203203202201207/30-Sekunden-zu-sp-t-Thriller-EDITION-211-by-Kaja-Bergmann.pdf
    • http://xiixmcuin.linkpc.net/1200203203202201201/Philosophie-in-30-Sekunden-Die-wichtigsten-Str-mungen-aus-der-Geschichte-der-Weltanschauungen-by-Barry-Loewer.pdf
    • http://xiixmcuin.linkpc.net/9203202203203207/Sieben-Monde-by-Marcus-Sedgwick.pdf
    • http://xiixmcuin.linkpc.net/1201204200202200206/Angelika-Mann---Was-treibt-mich-nur-Autobiografie-by-Angelika-Mann.pdf
    • http://xiixmcuin.linkpc.net/1200203202206206207/Sieben-Tage-nach-Sonntag-by-M-H-Sargent.pdf
    • http://xiixmcuin.linkpc.net/1201207209204200205/Sieben-St-dte-aus-Gold-by-Andreas-Zwengel.pdf
    • http://xiixmcuin.linkpc.net/1201204204202200204/Sprachgebrauch-Und-Sprachsch-pfung-in-Wieland-s-Prosaischen-Hauptwerken-N-mlich-Don-Sylvio-Di-Rosalva-Agathon-Der-Goldne-Spiegel-Geschichte-Des-Weisen