Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c5ea2bba0c80fab…

MALICIOUS

PDF

20.9 KB Created: 2020-03-15 21:08:36 +00:00 Authoring application: mPDF 5.7
MD5: 69692775d9397e231f0e3b8eac7d553e SHA-1: 60bf8553ec320faf18bf3231e0a3165ba76bb3e3 SHA-256: 1c5ea2bba0c80fabaf98a86e7b723cc4f2652fd1932b97cb1df434b6d2f0d172
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF document contains a heuristic firing for a link farm, with 27 external links embedded within its body. These links predominantly point to the domain 'ieuicufioao.myhome.cx' and appear to be disguised as book titles. This suggests a tactic to lure users into clicking malicious links, potentially leading to further malware downloads or phishing attempts. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/9554559556558552/Schuldig-Krimireihe-Hartmann-by-Jens-R-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9556557555559554/The-Thom-Hartmann-Reader-by-Thom-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550559553555/Fu-ball-Land-DDR-by-Frank-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550556559558/How-to-Keep-the-Love-of-Your-Life-by-Maureen-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9554559556557556/Schuldig-by-Manuela-Mendez.pdf
    • http://ieuicufioao.myhome.cx/9554559556558555/Schuldig-Alpentr-ume-by-Stefanie-Rosen.pdf
    • http://ieuicufioao.myhome.cx/9554559557553556/Als-ik-nee-zeg-voel-ik-me-schuldig-by-Manuel-J-Smith.pdf
    • http://ieuicufioao.myhome.cx/1551554550558559554/Todesmarsch-durch-Russland-Mein-Weg-in-die-Kriegsgefangenschaft-by-Klaus-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550557551551/U-188-A-German-Submariner-s-Account-of-the-War-at-Sea-1941-1945-by-Klaus-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9554559555550558/Schuldig-in-eigen-ogen-by-Agatha-Christie.pdf
    • http://ieuicufioao.myhome.cx/1551554550557556553/The-Annotated-Guide-for-Rns-to-the-Texas-Nursing-Practice-ACT-10th-Edition-by-James-H-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9554559556557557/Schuldig-mijn-verhaal-over-de-Deventer-moordzaak-by-Ernest-Louwes.pdf
    • http://ieuicufioao.myhome.cx/9554559558550552/Von-weltlicher-Obrigkeit-Vollst-ndige-Ausgabe-Wie-weit-man-ihr-Gehorsam-schuldig-sei-by-Martin-Luther.pdf
    • http://ieuicufioao.myhome.cx/9554559558556556/Niet-Schuldig-Meer-Geloof-je-Gods-Woord-of-de-aanklager-by-Clara-van-Dijk.pdf
    • http://ieuicufioao.myhome.cx/9554559558556552/Gerichtliche-Untersuchung-Wer-an-Dem-Blut-Christi-Jesu-Schuldig-Seye-by-Franz-Xaver-Brean.pdf
    • http://ieuicufioao.myhome.cx/9556557556557555/Spidermilk-by-Konrad-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/9556558551555551/Aesthetics-by-Nicolai-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/6551559550557556/LE-MAS-PROVEN-AL-by-Abbey-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550558553558/Samtliche-Werke-Band-7-1882-1901-Der-Soziale-Aufgabe-Der-Hoheren-Schulen-Beitrage-in-Rein-Enzyklopadisches-Handbuch-Der-Padagogik-Sowie-Andere-Abhandlungen-by-Otto-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9556557556557551/Dangerous-Urges-by-Konrad-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/955455955555055