Malicious PDF — malware analysis report

Static analysis result for SHA-256 36f95dfb968a6352…

MALICIOUS

PDF

15.0 KB Created: 2020-03-20 17:16:49 +00:00 Authoring application: mPDF 5.7
MD5: 5839dd656b27f9eda2c3368d6bbb3d86 SHA-1: 4e2d0fd79b584c29e03fc3467fc5617599ac366e SHA-256: 36f95dfb968a635295e7f96c993f26388f4c3a5b5c044416067b0199f7381acb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs all point to the same domain, weisncio.myhome.cx, and appear to be designed to redirect users to various book-related pages. This technique is often used to manipulate search engine rankings or to host malicious content behind a seemingly innocuous link. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/3627626629624621/The-Mermen-Trilogy-Boxed-Set-The-Mermen-Trilogy-1-3-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/4625627628621/Mermen-The-Mermen-Trilogy-1-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/4625627628622/MerMadmen-The-Mermen-Trilogy-2-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/3620628626626621/The-King-Trilogy-Boxed-Set-The-King-Trilogy-1-3-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/3623629623628/Mack-The-King-Trilogy-4-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/2620626627621629/The-Ten-Club-The-King-Trilogy-5-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/2626628626622624/King-for-a-Day-The-King-Trilogy-2-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/7622626624621627/Yours---Atemlose-Liebe-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/1629620621625623/Oh-Henry-OHellNo-2-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/1626624628624621/Digging-a-Hole-OHellNo-3-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/1620629623626626/Smart-Tass-OHellNo-1-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/4629626624622629/Tailored-for-Trouble-Happy-Pants-1-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/9622622627620/Leather-Pants-Happy-Pants-2-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/3624628625620628/Deadly-Trilogy-Boxed-Set-Deadly-Trilogy-1-3-by-Alexa-Grace.pdf
    • http://weisncio.myhome.cx/7629626624621627/The-Perception-Trilogy-Boxed-Set-by-Lee-Strauss.pdf
    • http://weisncio.myhome.cx/8628629621622/The-Ruby-Red-Trilogy-Boxed-Set-by-Kerstin-Gier.pdf
    • http://weisncio.myhome.cx/7620627625622/The-All-Souls-Trilogy-Boxed-Set-by-Deborah-Harkness.pdf
    • http://weisncio.myhome.cx/1626622629625621/Trylle-Trilogy-Boxed-Set-by-Amanda-Hocking.pdf
    • http://weisncio.myhome.cx/9626627626624628/The-Castell-Brothers-Trilogy-Boxed-Set-by-Izzy-Williams.pdf
    • http://weisncio.myhome.cx/7625626624/The-Librarian-s-Vampire-Assistant-The-Librarian-s-Vampire-Assistant-1-by-Mimi-Jean-Pamfiloff.pdf
    • http://weisncio.myhome.cx/4629626624622629/Tailored-for-Trouble-Happy-Pants-1-by-Mimi-Jean-Pamfilof