Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a0c0007681f7dfe…

MALICIOUS

PDF

23.5 KB Created: 2020-03-18 23:58:47 +00:00 Authoring application: mPDF 5.7
MD5: 650d5de35facab985c598311b66c0e2f SHA-1: b3ec07b8fb8931363f8b69109d4506940cfeb2ee SHA-256: 1a0c0007681f7dfe66ec2511dd992455d5c457884b654257c408db5cfa1e8e47
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain kitasdyu.myhome.cx. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. No scripts were extracted, and the document body was heavily obfuscated, but the sheer volume of links suggests a malicious intent to drive traffic to external resources.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/8875877872878/Saga-no-Gabai-Bachan---Nenek-Hebat-dari-Saga-by-Yoshichi-Shimada.pdf
    • http://kitasdyu.myhome.cx/9878870877879876/The-Impending-Storm-The-Imperium-Saga-The-Imperium-Saga-The-Imperium-Saga-by-Clifford-B-Bowyer.pdf
    • http://kitasdyu.myhome.cx/3870874871877877/Karlamagnus-Saga-The-Saga-Of-Charlemagne-and-His-Heroes-3-volume-set-by-Constance-B-Hieatt.pdf
    • http://kitasdyu.myhome.cx/1875875875871878/The-Saga-of-I-The-Complete-Collection-Saga-of-I-1-3-by-Kenneth-W-Cain.pdf
    • http://kitasdyu.myhome.cx/2870877877875877/Saga-Book-One-Saga-1-3-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/5873878877/Saga-Vol-7-Saga-7-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/3875879870/Saga-Vol-6-Saga-6-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/9875877871/Saga-Vol-4-Saga-4-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/1870870871878/Saga-Vol-3-Saga-3-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/1873875879876870/Bagthorpes-V-the-World-Being-the-Fourth-Part-of-the-Bagthorpe-Saga-The-Bagthorpe-Saga-4-by-Helen-Cresswell.pdf
    • http://kitasdyu.myhome.cx/9873879872878876/Olafs-Saga-Hins-Helga-En-Kort-Saga-on-Kong-Olaf-Den-Hellige-Fra-Anden-Halvdeel-AF-Det-Tolfte-Aarhundrede-Efter-Et-Gammelt-Pergaments-Haandskrift-I-Universitets-Bibliotheket-I-Upsala-by-Rudolph-Keyser.pdf
    • http://kitasdyu.myhome.cx/1873875879878871/Bagthorpes-Abroad-Being-the-Fifth-Part-of-the-Bagthorpe-Saga-The-Bagthorpe-Saga-5-by-Helen-Cresswell.pdf
    • http://kitasdyu.myhome.cx/4877877873877875/Freelance-Saga-Episode-6-Freelance-Saga-6-by-Scottie-Futch.pdf
    • http://kitasdyu.myhome.cx/3870879873872877/The-Cobra-s-Lair-A-Black-Brothers-Saga-Tale-The-Black-Brothers-Saga-Book-1-by-M-G-Floyd.pdf
    • http://kitasdyu.myhome.cx/4871878873870873/Excel-Saga-Vol-1-Excel-Saga-1-by-Koshi-Rikudo.pdf
    • http://kitasdyu.myhome.cx/9878870878874875/The-Changing-Tides-The-Imperium-Saga-Fall-of-the-Imperium-Trilogy-The-Imperium-Saga-Fall-of-the-Imperium-Trilogy-The-Imperium-Saga-Fall-of-the-Imperium-Trilogy-by-Clifford-B-Bowyer.pdf
    • http://kitasdyu.myhome.cx/4870875873876875/Saga-21-by-Brian-K-Vaughan.pdf
    • http://kitasdyu.myhome.cx/4871872877878874/The-Fairytail-Saga-Box-Set-by-S-K-Munt.pdf
    • http://kitasdyu.myhome.cx/1876874872878873/The-Kinsman-Saga-by-Ben-Bova.pdf
    • http://kitasdyu.myhome.cx/1870878877870874/The-Evolved-New-Era-Saga-1-by-K-T-Webb.pdf