Malicious PDF — malware analysis report

Static analysis result for SHA-256 f335ba2630babca8…

MALICIOUS

PDF

16.6 KB Created: 2019-05-02 01:40:43 +01:00 Authoring application: mPDF 5.7
MD5: 86db373f2d17f40e708aed744a266bd4 SHA-1: d0c300616237bab65e30aa7d48b3ef7388a12346 SHA-256: f335ba2630babca8f17bc3745930be88c65284ce0ba38839c149ce27954e1f6f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a heuristic firing for a link farm, indicating a large number of embedded external links. While the document body is unreadable, the presence of numerous links suggests a deceptive purpose, potentially for SEO manipulation or distributing further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1205208208201203/Dolly-and-the-Bird-of-Paradise-Johnson-Johnson-6-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/1205208208207200/Dolly-and-the-Singing-Bird-Johnson-Johnson-1-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/1205208209202207/Dolly-and-the-Doctor-Bird-Johnson-Johnson-3-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/1205208208208208/Dolly-and-the-Starry-Bird-Johnson-Johnson-4-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/1205208208206203/Ibiza-Surprise-Johnson-Johnson-2-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/4208209209205201/Lady-Bird-Johnson-An-Oral-History-by-Michael-L-Gillette.pdf
    • http://xiixmcuin.linkpc.net/1208205209208205/Poverty-Politics-and-Race-The-View-from-Down-Here-by-Dorothy-J-Inman-Johnson.pdf
    • http://xiixmcuin.linkpc.net/8202209205203200/Darwinism-Defeated-The-Johnson-Lamoureux-Debate-on-Biological-Origins-by-Phillip-E-Johnson.pdf
    • http://xiixmcuin.linkpc.net/1203209206205203/I-Married-Adventure-The-Lives-of-Martin-and-Osa-Johnson-by-Osa-Johnson.pdf
    • http://xiixmcuin.linkpc.net/7207208207200204/Shreveport-and-Bossier-City-Photographs-and-Text-by-Neil-Johnson-With-a-Foreword-by-Jim-Montgomery-by-Neil-Johnson.pdf
    • http://xiixmcuin.linkpc.net/1202202202200209/House-of-Niccolo-Series-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/7203200202205/Gemini-The-House-of-Niccolo-8-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/3208200203200206/Checkmate-The-Lymond-Chronicles-6-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/5200209204207208/The-Papers-of-Andrew-Johnson-Volume-6-1862-1864-by-Andrew-Johnson.pdf
    • http://xiixmcuin.linkpc.net/1208202208205208/Money-Changed-Hands-A-Peter-Johnson-Collection-by-Peter-Johnson.pdf
    • http://xiixmcuin.linkpc.net/4200201203205/The-Ringed-Castle-The-Lymond-Chronicles-5-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/4202207200207/Queens-Play-The-Lymond-Chronicles-2-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/3209207201206/The-Disorderly-Knights-The-Lymond-Chronicles-3-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/1201206200206208201/Edinburgh-The-Dorothy-Dunnett-Guide-by-Nicky-Cannon.pdf
    • http://xiixmcuin.linkpc.net/3208209200208207/Pawn-in-Frankincense-The-Lymond-Chronicles-4-by-Dorothy-Dunnett.pdf
    • http://xiixmcuin.linkpc.net/8202209205203200/Darwinism-Defeated