Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd3483e210822cd5…

MALICIOUS

PDF

18.2 KB Created: 2019-05-07 03:46:46 +01:00 Authoring application: mPDF 5.7
MD5: 7d5c99f3c93ee77a0ec87964529541b7 SHA-1: 196791b95636474fdfd0d43073a8b4286c144b41 SHA-256: fd3483e210822cd52cbc9d3f56eba3906cf6b18d612ac90d34cb592e8018ab07
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The URLs are hosted on a dynamic DNS domain, which is suspicious. No scripts were extracted from this sample, and the document body was heavily obfuscated, limiting further analysis of the exact user-facing lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4209204201203207/Theory-and-Treatment-of-Anorexia-Nervosa-and-Bulimia-Biomedical-Sociocultural-and-Psychological-Perspectives-by-Steven-Emmett.pdf
    • http://xiixmcuin.linkpc.net/4209203208208201/Anorexia-Nervosa-A-Guide-to-Recovery-by-Lindsey-Hall.pdf
    • http://xiixmcuin.linkpc.net/4209204203206203/Anorexia-Nervosa-Finding-the-Life-Line-by-Barbara-C-Unell.pdf
    • http://xiixmcuin.linkpc.net/4209203208206206/Ten-Mile-Morning-My-Journey-Through-Anorexia-Nervosa-by-Adam-Lamparello.pdf
    • http://xiixmcuin.linkpc.net/4209204201204207/Eating-Disorders-Obesity-Anorexia-Nervosa-And-The-Person-Within-by-Hilde-Bruch.pdf
    • http://xiixmcuin.linkpc.net/4209204203205208/The-Thin-Woman-Feminism-Post-Structuralism-and-the-Social-Psychology-of-Anorexia-Nervosa-by-Helen-Malson.pdf
    • http://xiixmcuin.linkpc.net/3205202209204205/The-Luckiest-Girl-in-the-World-by-Steven-Levenkron.pdf
    • http://xiixmcuin.linkpc.net/4201209202209208/Treating-Ty-Veteran-2-by-Bobby-Michaels.pdf
    • http://xiixmcuin.linkpc.net/8208205203203200/Tovi-the-Penguin-Goes-Trick-or-Treating-by-Janina-Rossiter.pdf
    • http://xiixmcuin.linkpc.net/4209203207204201/Empty-A-Story-of-Anorexia-by-Christie-Pettit.pdf
    • http://xiixmcuin.linkpc.net/7200205204201205/Treating-Complex-Trauma-in-Adolescents-and-Young-Adults-by-John-N-Briere.pdf
    • http://xiixmcuin.linkpc.net/4206201206205206/Cultural-Cancer-Treating-the-Disease-of-Political-Correctness-by-Daryl-Kane.pdf
    • http://xiixmcuin.linkpc.net/1208206207209206/Treating-Trauma-and-Traumatic-Grief-in-Children-and-Adolescents-by-Judith-A-Cohen.pdf
    • http://xiixmcuin.linkpc.net/1200203203201207202/Healing-Physician-Burnout-Diagnosing-Preventing-and-Treating-by-Quint-Studer.pdf
    • http://xiixmcuin.linkpc.net/9207201200207207/Treating-Traumatized-Children-Risk-Resilience-and-Recovery-by-Danny-Brom.pdf
    • http://xiixmcuin.linkpc.net/4209204203205209/Starving-A-Personal-Journey-Through-Anorexia-by-Christie-Pettit.pdf
    • http://xiixmcuin.linkpc.net/3204202202202/Wasted-A-Memoir-of-Anorexia-and-Bulimia-by-Marya-Hornbacher.pdf
    • http://xiixmcuin.linkpc.net/3207208206209206/Skills-Training-Manual-for-Treating-Borderline-Personality-Disorder-by-Marsha-M-Linehan.pdf
    • http://xiixmcuin.linkpc.net/3208205209205205/Rebuilding-Shattered-Lives-Treating-Complex-PTSD-and-Dissociative-Disorders-by-James-A-Chu.pdf
    • http://xiixmcuin.linkpc.net/7203207205205202/Wounded-by-Reality-Understanding-and-Treating-Adult-Onset-Trauma-by-Ghislaine-Boulanger.pdf
    • http://xiixmcuin.linkpc.net/3205202209204205/The-Luckiest-Girl-in-the-World-by-Steven-Lev