Malicious PDF — malware analysis report

Static analysis result for SHA-256 f033602ada82a063…

MALICIOUS

PDF

27.2 KB Created: 2019-04-30 03:46:58 +01:00 Authoring application: mPDF 5.7
MD5: 7c11ec747d9eec1d8a2555bf1fbd0cd7 SHA-1: 81ca876525bdbd63a984dbaad55639bcf5f84001 SHA-256: f033602ada82a0636c05fc2d672f6c917c7c74abe9034db1475754aa500e9d4a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with 32 external links embedded within the document. These links, such as 'http://xiixmcuin.linkpc.net/1200206208208200207/The-Limits-of-Empire-European-Imperial-Formations-in-Early-Modern-World-History-Essays-in-Honor-of-Geoffrey-Parker-by-Tonio-Andrade.pdf', are likely used to redirect users to malicious websites or download further malware. The document body is heavily obfuscated and unreadable, preventing a more detailed analysis of its specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc
    • http://xiixmcuin.linkpc.net/1200206208208200207/The-Limits-of-Empire-European-Imperial-Formations-in-Early-Modern-World-History-Essays-in-Honor-of-Geoffrey-Parker-by-Tonio-Andrade.pdf
    • http://xiixmcuin.linkpc.net/1200206208206209209/Sea-Rovers-Silver-and-Samurai-Maritime-East-Asia-in-Global-History-1550-1700-by-Tonio-Andrade.pdf
    • http://xiixmcuin.linkpc.net/1201200203208201209/Early-Modern-European-Society-by-Henry-Kamen.pdf
    • http://xiixmcuin.linkpc.net/1200206208206200204/Lost-Colony-The-Untold-Story-of-China-s-First-Great-Victory-Over-the-West-by-Tonio-Andrade.pdf
    • http://xiixmcuin.linkpc.net/6204200206206207/The-Modern-World-System-II-Mercantilism-and-the-Consolidation-of-the-European-World-Economy-1600-1750-by-Immanuel-Wallerstein.pdf
    • http://xiixmcuin.linkpc.net/6206201200200202/The-End-of-the-European-Era-1890-to-the-Present-The-Norton-History-of-Modern-Europe-by-Felix-Gilbert.pdf
    • http://xiixmcuin.linkpc.net/1206205201208208/A-Mad-Catastrophe-The-Outbreak-of-World-War-I-and-the-Collapse-of-the-Habsburg-Empire-by-Geoffrey-Wawro.pdf
    • http://xiixmcuin.linkpc.net/2201202209205/The-Culture-of-Bruising-Essays-on-Prizefighting-Literature-and-Modern-American-Culture-by-Gerald-Early.pdf
    • http://xiixmcuin.linkpc.net/6206206204204205/Three-Ways-to-Be-Alien-Travails-amp-Encounters-in-the-Early-Modern-World-by-Sanjay-Subrahmanyam.pdf
    • http://xiixmcuin.linkpc.net/1200209209207209206/The-Hashemites-in-the-Modern-Arab-World-Essays-in-Honour-of-the-Late-Professor-Uriel-Dann-by-Asher-Susser.pdf
    • http://xiixmcuin.linkpc.net/5202201209209201/A-People-s-History-of-the-Second-World-War-Resistance-Versus-Empire-by-Donny-Gluckstein.pdf
    • http://xiixmcuin.linkpc.net/5201203202203203/Artisans-in-Early-Imperial-China-by-Anthony-Barbieri-Low.pdf
    • http://xiixmcuin.linkpc.net/5209202202203/The-Cartoon-History-of-the-Modern-World-Part-2-From-the-Bastille-to-Baghdad-by-Larry-Gonick.pdf
    • http://xiixmcuin.linkpc.net/8209201204200/Empire-the-Novel-of-Imperial-Rome-Roma-2-by-Steven-Saylor.pdf
    • http://xiixmcuin.linkpc.net/1207204200200205/Kalpa-Imperial-The-Greatest-Empire-That-Never-Was-by-Ang-lica-Gorodischer.pdf
    • http://xiixmcuin.linkpc.net/4204205209208204/Republic-and-Empire-Imperial-Stars-2-by-John-F-Carr.pdf
    • http://xiixmcuin.linkpc.net/5204202201205201/Judaism-Discover-the-History-Faith-and-Culture-That-Have-Shaped-the-Modern-Jewish-World-by-Douglas-Charing.pdf
    • http://xiixmcuin.linkpc.net/9209202205204201/Star-Wars-Empire-Volume-3-The-Imperial-Perspective-by-Paul-Alden.pdf
    • http://xiixmcuin.linkpc.net/5201203203206207/Six-Galleons-for-the-King-of-Spain-Imperial-Defense-in-the-Early-Seventeenth-Century-by-Carla-Rahn-Phillips.pdf
    • http://xiixmcuin.linkpc.net/4207204202207200/World-War-2-History-s-10-Most-Incredible-Women-World-War-II-True-Accounts-Of-Remarkable-Women-Heroes-WWII-history-WW2-War-books-world-war-2-books-war-history-World-war-2-women-by-Stephanie-T-McRae.pdf