Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcfcec09bce83d13…

MALICIOUS

PDF

20.4 KB Created: 2019-04-30 01:40:50 +01:00 Authoring application: mPDF 5.7
MD5: 424445c3a22844c8a802b0f5ae3408f0 SHA-1: 4fd78ffabb1e00ade98ef9c12ca748ae6261252d SHA-256: dcfcec09bce83d1399bca7afde7f14be21a2d165270ddb81f8ceca80461fcf6f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. It contains numerous embedded URLs, with the first identified URL being http://xiixmcuin.linkpc.net/1201202207203207200/Indiestructible-Inspiring-Stories-from-the-Publishing-Jungle-by-Jessica-Bell.pdf. The document body, though heavily obfuscated, also contains similar URLs. This suggests a phishing or social engineering attack where the embedded links are used to redirect users to potentially harmful content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201202207203207200/Indiestructible-Inspiring-Stories-from-the-Publishing-Jungle-by-Jessica-Bell.pdf
    • http://xiixmcuin.linkpc.net/4201202208206209/Sway-With-Me-Inspiring-the-Greek-Billionaire-1-by-Shelly-Bell.pdf
    • http://xiixmcuin.linkpc.net/1203207201/Inspiring-You-Unraveling-You-4-by-Jessica-Sorensen.pdf
    • http://xiixmcuin.linkpc.net/3206205200204202/Inspiring-You-Unraveling-You-4-by-Jessica-Sorensen.pdf
    • http://xiixmcuin.linkpc.net/4200201205203209/Rudyard-Kipling-The-Jungle-Book-The-Second-Jungle-Book-Just-So-Stories-Puck-of-Pook-s-Hill-Stalky-amp-Co-Kim-by-Rudyard-Kipling.pdf
    • http://xiixmcuin.linkpc.net/2209200207208/The-Book-by-Jessica-Bell.pdf
    • http://xiixmcuin.linkpc.net/3205206207205205/The-Book-by-Jessica-Bell.pdf
    • http://xiixmcuin.linkpc.net/4206206201201202/String-Bridge-by-Jessica-Bell.pdf
    • http://xiixmcuin.linkpc.net/3203205207204206/From-Failure-to-Success-A-Treasury-of-50-Inspiring-Stories-by-Abhinav-Kushwaha.pdf
    • http://xiixmcuin.linkpc.net/8203201202201/SHE-a-short-story-in-verse-by-Jessica-Bell.pdf
    • http://xiixmcuin.linkpc.net/4206207209203209/A-Passion-and-a-Dream-Inspiring-Stories-of-Actors-Writers-et-al-on-the-Eve-of-Their-Big-Break-by-Creativly.pdf
    • http://xiixmcuin.linkpc.net/3200204200204206/Champions-15-Inspiring-Comeback-Stories-from-Sports-and-Life-by-George-Castle.pdf
    • http://xiixmcuin.linkpc.net/1200205206201209202/Hope-Conquers-All-Inspiring-Stories-of-Love-and-Healing-from-CaringBridge-by-Sona-Mehring.pdf
    • http://xiixmcuin.linkpc.net/5200202208209205/The-Magic-of-Christmas-Miracles-An-All-New-Collection-Of-Inspiring-True-Stories-by-Jamie-Miller.pdf
    • http://xiixmcuin.linkpc.net/4200209200204203/Sunny-Side-Up-Inspiring-Stories-for-Tough-Times-Women-Dog-amp-Cat-Lovers-by-B-J-Taylor.pdf
    • http://xiixmcuin.linkpc.net/4200209208209208/Take-Me-Home-The-Inspiring-Stories-of-20-Entrepreneurs-from-Small-Town-India-with-Big-Time-Dreams-by-Rashmi-Bansal.pdf
    • http://xiixmcuin.linkpc.net/6209209203207201/Holy-Brother-Inspiring-Stories-and-Enchanted-Tales-about-Rabbi-Shlomo-Carlebach-by-Yitta-Halberstam-Mandelbaum.pdf
    • http://xiixmcuin.linkpc.net/9201208203209202/Blood-Jungle-Ballet-Jungle-Beat-4-by-John-Enright.pdf
    • http://xiixmcuin.linkpc.net/4203205207206202/Borneo-Tom-Stories-and-Sketches-of-Love-Travel-and-Jungle-Family-in-Tropical-Asia-by-Tom-McLaughlin.pdf
    • http://xiixmcuin.linkpc.net/1208205201200204/Milly-s-Jungle-Adventures-The-Jungle-Talent-Show-by-Uma-S-.pdf