Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec4fd1580265bd0c…

MALICIOUS

PDF

58.3 KB Created: 2019-04-30 04:25:45 +01:00 Authoring application: mPDF 5.7
MD5: 50dddd7aaeb493e96ed03e5603feb295 SHA-1: 0b35a7b35891fbd9ba1a43d13009654296bd58f1 SHA-256: ec4fd1580265bd0cfdcb170ba1a948f65a5250cf861dce13f57f5afc0f75015f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for further malicious activity. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2202205203201201/Sports-and-Labor-in-the-United-States-by-Michael-Schiavone.pdf
    • http://xiixmcuin.linkpc.net/1200201204203203201/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-1912-Vol-5-of-6-Transcript-of-Record-William-F-Kettenbach-and-George-H-Kester-Plaintiffs-in-Error-Vs-The-United-States-of-America-Defendant-in-Error-Pages-1521-to-1916-Inclusive-by-United-States-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/8205202208201207/Un-the-United-States-Court-of-Appeals-for-the-Ninth-Circuit-Miner-Bruce-and-Julia-M-Bruce-Appellants-vs-Mary-E-Murray-Appelle-Transcript-of-Record-Upon-Appeal-from-the-United-States-District-Court-for-the-District-of-Alaska-Second-Division-by-United-States-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/5207202206201207/Aeronautical-Sports-Sports-Aeronautiques-Bicycling-and-Cycling-Bicyclette-Et-Cyclisme-Equestrian-Sports-Sports-Equestres-Motor-Sports-Sports-Motorises-Target-Sports-Sports-de-Tir-Sur-Cible-by-I-Iingridd-Draayer.pdf
    • http://xiixmcuin.linkpc.net/1201203200201208201/A-People-s-History-of-Sports-in-the-United-States-250-Years-of-Politics-Protest-People-and-Play-by-Dave-Zirin.pdf
    • http://xiixmcuin.linkpc.net/1200201204203204200/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Vol-3-of-6-Transcript-of-Record-William-F-Kettenbach-Geo-H-Kester-and-William-Dwyer-Plaintiffs-in-Error-vs-the-United-States-of-America-Defendant-in-Error-Pages-817-to-1232-Inclusi-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/8205202208201209/United-States-Circuit-Court-of-Appeals-Fo-the-Ninth-Circuit-The-United-States-of-America-Appellant-vs-Komada-and-Co-Appelle-Condensed-Transcript-of-Record-Upon-Appeal-from-the-United-States-Circuit-Court-for-Northern-District-of-California-by-U-S-Court-of-Appeals-Ninth-Circuit.pdf
    • http://xiixmcuin.linkpc.net/8200200201204202/The-Collection-of-United-States-Cents-of-Dr-S-T-Millard-Together-with-the-Collections-of-United-States-and-Pioneer-Gold-and-Silver-Coins-of-Mr-Edward-Heissler-Chicago-and-Other-Properties-To-Be-Sold-at-Auction-Thursday-March-18th-1915-by-B-Max-Mehl.pdf
    • http://xiixmcuin.linkpc.net/9208202200203/A-Queer-History-of-the-United-States-by-Michael-Bronski.pdf
    • http://xiixmcuin.linkpc.net/6205206203207206/Vincent-s-Semi-Annual-United-States-Register-A-Work-in-Which-the-Principal-Events-of-Every-Half-Year-Occuring-in-the-United-States-Are-Recorded-Each-Arranged-Under-the-Day-of-Its-Date-This-Volume-Contains-the-Events-Transpiring-Between-the-1st-of-Janua-by-Francis-Vincent.pdf
    • http://xiixmcuin.linkpc.net/8205202207209200/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-John-D-Nagle-as-Commissioner-of-Immigration-for-the-Port-of-San-Francisco-California-Appellant-vs-Dong-Ming-Appelle-Transcript-of-Record-by-United-States-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/7206200201209204/The-United-States-of-America-versus-Theodore-John-Kaczynski-Ethics-Power-and-the-Invention-of-the-Unabomber-by-Michael-Mello.pdf
    • http://xiixmcuin.linkpc.net/1200201204203203209/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Vol-1-of-6-Transcript-of-Record-William-F-Kettenbach-and-George-H-Kester-Plaintiffs-in-Error-vs-the-U-S-of-America-Defendant-in-Error-Pages-1-to-304-Inclusive-Upon-Writ-of-Error-T-by-United-States-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/1200203206204209/The-World-Must-Know-The-History-Of-The-Holocaust-As-Told-In-The-United-States-Holocaust-Memorial-Museum-by-Michael-Berenbaum.pdf
    • http://xiixmcuin.linkpc.net/1201208202201204208/Harper-s-Encyclop-dia-of-United-States-History-from-458-A-D-to-1906-Harper-s-Encyclop-dia-of-United-States-History-from-458-A-D-to-1906-Volume-3-by-Benson-John-Lossing.pdf
    • http://xiixmcuin.linkpc.net/8205202208200207/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Moss-and-Company-Appellant-Vs-P-H-McCarthy-Mayor-of-the-City-and-County-of-San-Francisco-John-F-Seymour-and-D-A-White-Chief-of-Police-of-the-City-and-County-of-San-Francisco-Appelle-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/1200201204203203208/United-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Vol-5-of-6-Transcript-of-Record-William-F-Kettenbach-Geo-H-Kester-and-William-Dwyer-Plaintiffs-in-Error-vs-the-United-States-of-America-Defendant-in-Error-Pages-1649-to-2064-Inclu-by-U-S-Court-of-Appeals-Ninth-Circuit.pdf
    • http://xiixmcuin.linkpc.net/5209205206208207/Olympics---Sports-Sports-by-Year-Summer-Sports-Winter-Sports-Alpine-Skiing-Archery-Artistic-Gymnastics-Athletics-Badminton-Baseball-Basketball-Beach-Volleyball-Biathlon-BMX-Bobsleigh-Boxing-Canoe-Kayak-Slalom-by-Source-Wikia.pdf
    • http://xiixmcuin.linkpc.net/5200200207200/The-United-States-of-Air-by-J-M-Porup.pdf
    • http://xiixmcuin.linkpc.net/8205202207209206/Unites-States-Circuit-Court-of-Appeals-for-the-Ninth-Circuit-Robert-S-Hale-Appellant-Vs-Ames-Realty-Company-a-Corporation-Et-Al-Appelles-Transcript-of-Records-by-United-States-Circuit-Court-of-Appeals.pdf
    • http://xiixmcuin.linkpc.net/8205202208201207/Un-the-United-States-Court-of-Appeals-for-the-Ninth-Circuit-Miner-Bruce-and-Julia-M-Bruce-Appellants-vs-Mary-E-Murray-Appelle-Transcript-of-Record-Upon-Appeal-from-the-United-States-District-Court-for-the-District-of-Alaska-S