Malicious PDF — malware analysis report

Static analysis result for SHA-256 eef9bc7b096a801b…

MALICIOUS

PDF

17.6 KB Created: 2019-05-07 05:19:06 +01:00 Authoring application: mPDF 5.7
MD5: 43186b7453015d5493b86c8a1183edd9 SHA-1: c8bac0394ac0231859801114f4a8012bb3c62464 SHA-256: eef9bc7b096a801bdc90ceb75b9a0648922e25dcb9ef3b9cbd3f1ac3e7bbcd66
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname (xiixmcuin.linkpc.net) suggest a potential for hosting malicious content or redirecting users to phishing sites. The document body was not parsable, limiting further analysis of its direct intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201209206207200205/Chi-Nei-Tsang-Chi-Massage-for-the-Vital-Organs-by-Mantak-Chia.pdf
    • http://xiixmcuin.linkpc.net/5204202201209205/On-Some-Symptoms-Which-Simulate-Disease-of-the-Pelvic-Organs-in-Women-And-Their-Treatment-by-Alo-Piesto-Myo-Kinetics-Massage-and-by-Auto-Piesto-Myo-Kinetics-by-Andrea-Rabagliati.pdf
    • http://xiixmcuin.linkpc.net/1209207201205206/The-Massage-Disadvantage-What-Doctors-Know-About-Making-Money-That-Massage-Therapists-Don-t-by-Matthew-Lewis-D-C-.pdf
    • http://xiixmcuin.linkpc.net/1209206204201208/The-Woman-Who-Lost-China-by-Rhiannon-Jenkins-Tsang.pdf
    • http://xiixmcuin.linkpc.net/2200207202205209/A-Modern-History-of-Hong-Kong-by-Steve-Tsang.pdf
    • http://xiixmcuin.linkpc.net/1201209206206202203/A-Garden-of-Organs-by-Elvin-Ramos.pdf
    • http://xiixmcuin.linkpc.net/1201209206207204203/Fragile-Human-Organs-by-Ross-Halfin.pdf
    • http://xiixmcuin.linkpc.net/1201209206207205203/State-Organs-Transplant-Abuse-in-China-by-David-Matas.pdf
    • http://xiixmcuin.linkpc.net/1201209206208200207/Al-Ghazzali-on-the-Treatment-of-the-Lust-of-the-Stomach-and-the-Sexual-Organs-by-Abu-Hamid-al-Ghazali.pdf
    • http://xiixmcuin.linkpc.net/4206203202201201/Massage-by-Bi-Feiyu.pdf
    • http://xiixmcuin.linkpc.net/1201209206207204202/Kidney-for-Sale-by-Owner-Human-Organs-Transplantation-and-the-Market-by-Mark-J-Cherry.pdf
    • http://xiixmcuin.linkpc.net/1201207208204209201/Massage-by-Nitya-Lacroix.pdf
    • http://xiixmcuin.linkpc.net/4204209203207200/Heated-Massage-by-K-C-Bloom.pdf
    • http://xiixmcuin.linkpc.net/4202203203204201/Massage-for-Lovers-by-Nitya-Lacroix.pdf
    • http://xiixmcuin.linkpc.net/9208206202201/The-Medium-is-the-Massage-by-Marshall-McLuhan.pdf
    • http://xiixmcuin.linkpc.net/5206202205202/A-Beautiful-Mind-A-Beautiful-Life-The-Bubz-Guide-to-Being-Unstoppable-by-Lindy-Tsang.pdf
    • http://xiixmcuin.linkpc.net/4207202202209/The-Medium-is-the-Massage-An-Inventory-of-Effects-by-Marshall-McLuhan.pdf
    • http://xiixmcuin.linkpc.net/9209200207204203/Only-for-Woman-Eine-Massage-der-besonderen-Art-by-Dagmar-Heyer.pdf
    • http://xiixmcuin.linkpc.net/6205205206209203/Pratique-du-massage-tao-ste-Poche-t-2962-by-Galya-Ortega.pdf
    • http://xiixmcuin.linkpc.net/9200207204200205/Infant-Massage-A-Handbook-for-Loving-Parents-by-Vimala-Schneider-McClure.pdf
    • http://xiixmcuin.linkpc.net/1201209206207205203/St