Malicious PDF — malware analysis report

Static analysis result for SHA-256 31fea4c7fa0126c8…

MALICIOUS

PDF

17.3 KB Created: 2020-03-18 18:08:51 +00:00 Authoring application: mPDF 5.7
MD5: 3a9cab8a7812cd3e310d8127ad2da933 SHA-1: 8f619e620624ea8d7f9a956f0cf7d3d729e8586d SHA-256: 31fea4c7fa0126c85dc9cab26cc44ac41e00c413b28c1daeadade4ced6e60958
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, all pointing to the same domain 'weisncio.myhome.cx'. This suggests a link farm or traffic-driving scheme, likely intended to lure users to download further malicious content or visit phishing pages. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/3621626621622623/Dachshund-Disaster-Pet-Trouble-8-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/3621626621621627/Oh-No-Newf-Pet-Trouble-5-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/3621626621623621/Mud-Puddle-Poodle-Pet-Trouble-3-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/3621626621620624/Runaway-Retriever-Pet-Trouble-1-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/3625628626621628/Smarty-Pants-Sheltie-Pet-Trouble-6-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/5623624627626621/Crusoe-the-Celebrity-Dachshund-2019-Box-Calendar-by-Ryan-Beauchesne.pdf
    • http://weisncio.myhome.cx/4621623621623626/Trouble-in-Paradise-Trouble-Katie-amp-Tyler-s-Story-2-by-Emme-Rollins.pdf
    • http://weisncio.myhome.cx/5623624627625624/Crusoe-the-Celebrity-Dachshund-2019-Wall-Calendar-by-Ryan-Beauchesne.pdf
    • http://weisncio.myhome.cx/5623624627626623/Crusoe-the-Celebrity-Dachshund-2018-Engagement-Calendar-by-Ryan-Beauchesne.pdf
    • http://weisncio.myhome.cx/5623624625628629/Crusoe-the-Celebrity-Dachshund-Adventures-of-the-Wiener-Dog-Extraordinaire-by-Ryan-Beauchesne.pdf
    • http://weisncio.myhome.cx/2620629627622621/Meeting-Trouble-Trouble-Rob-amp-Sabrina-s-Story-1-by-Emme-Rollins.pdf
    • http://weisncio.myhome.cx/1622627625622628/Alien-Disaster-Alien-Disaster-Trilogy-Book-1-by-Rob-May.pdf
    • http://weisncio.myhome.cx/3623629626625628/Trouble-Makes-a-Comeback-Trouble-2-by-Stephanie-Tromly.pdf
    • http://weisncio.myhome.cx/4626628621622628/Trouble-s-Brewing-Stirring-Up-Trouble-2-by-Juli-Alexander.pdf
    • http://weisncio.myhome.cx/3624627624628622/The-Trouble-With-Love-Texas-Trouble-2-by-Becky-McGraw.pdf
    • http://weisncio.myhome.cx/8627628623625626/Schrodinger-s-Dachshund-A-Novel-of-Espionage-Astounding-Science-and-Wiener-Dogs-by-Petronius-Jablonski.pdf
    • http://weisncio.myhome.cx/4621627622626621/Destination-Dachshund-A-Travel-Memoir-Three-Months-Three-Generations-amp-Sixty-Dachshunds-by-Lisa-Fleetwood.pdf
    • http://weisncio.myhome.cx/2621621627624626/Chasing-Trouble-Trouble-2-by-Courtney-B-Jones.pdf
    • http://weisncio.myhome.cx/3627621625625620/Trouble-Never-Sleeps-Trouble-3-by-Stephanie-Tromly.pdf
    • http://weisncio.myhome.cx/4625623625627625/Looking-for-Trouble-Trouble-1-by-Erin-Kern.pdf
    • http://weisncio.myhome.cx/2620629627622621/Meeting-Trouble-Trouble-Rob-amp-Sabrina-s-Story