Malicious PDF — malware analysis report

Static analysis result for SHA-256 372ccc83bb57ad4b…

MALICIOUS

PDF

19.7 KB Created: 2020-03-20 14:11:28 +00:00 Authoring application: mPDF 5.7
MD5: 8f9f4576f7f2a7c132e5ef8ca9f5a59b SHA-1: 2829cc38a93182919b8364301783eb74743f2307 SHA-256: 372ccc83bb57ad4bcfb2ec7913b855dfdc661df9fdd3cf6530c91321a00c04e2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, constituting a link farm. The primary heuristic indicates this is a PDF_SEO_LINK_FARM, suggesting the document's purpose is to drive traffic to these external sites. No scripts were extracted from this sample. The dominant host for these links is weisncio.myhome.cx.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/5622622627622/Torture-the-Artist-Joey-Goebel-by-Joey-Goebel.pdf
    • http://weisncio.myhome.cx/7622625628629/Grave-Images-by-Jenny-Goebel.pdf
    • http://weisncio.myhome.cx/6624624620627/Torture-the-Artist-by-Joey-Goebel.pdf
    • http://weisncio.myhome.cx/1620628626629628628/Behold-the-Pattern-by-Goebel-Music.pdf
    • http://weisncio.myhome.cx/1620628626629628622/M-I-Hummel-the-Golden-Anniversary-Album-by-Goebel.pdf
    • http://weisncio.myhome.cx/1620628626629628623/Summer-Man-and-Other-Black-Comedies-by-Joey-Goebel.pdf
    • http://weisncio.myhome.cx/8628626624629624/Eichendorff-s-Scholarly-Reception-A-Survey-by-Robert-O-Goebel.pdf
    • http://weisncio.myhome.cx/2627621627625629/Tournament-of-Losers-by-Megan-Derr.pdf
    • http://weisncio.myhome.cx/3625621621620628/Tournament-Poker-And-The-Art-Of-War-by-David-Apostolico.pdf
    • http://weisncio.myhome.cx/1620628626629627629/Humor-Writing-Activities-for-the-English-Classroom-by-Bruce-A-Goebel.pdf
    • http://weisncio.myhome.cx/1620628626629629623/The-Deepest-Longing-Of-Young-People-Loving-Without-Conditions-by-Jerry-Goebel.pdf
    • http://weisncio.myhome.cx/1620623625623629621/Blue-Mage-Equinox-Tournament-of-Mages-2-by-Cleave-Bourbon.pdf
    • http://weisncio.myhome.cx/4629626627623625/The-Tournament-at-Gorlan-Ranger-s-Apprentice-The-Early-Years-1-by-John-Flanagan.pdf
    • http://weisncio.myhome.cx/1620625627621627623/How-March-Became-Madness-How-the-NCAA-Tournament-Became-the-Greatest-Sporting-Event-in-America-by-Eddie-Einhorn.pdf
    • http://weisncio.myhome.cx/8629625620625621/March-1939-Before-the-Madness--The-Story-of-the-First-NCAA-Basketball-Tournament-Champions-by-Terry-Frei.pdf
    • http://weisncio.myhome.cx/1620626628623627625/The-Raiser-s-Edge-Tournament-Poker-Strategies-for-Today-s-Aggressive-Game-by-Bertrand-Grospellier.pdf
    • http://weisncio.myhome.cx/5628629628626629/Yu-Yu-Hakusho-Volume-18-The-Demon-Plane-Unification-Tournament-Yu-Yu-Hakusho-18-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627625629/Yu-Yu-Hakusho-Volume-6-The-Dark-Tournament-Yu-Yu-Hakusho-6-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/4625626621624627/Hikaru-no-Go-Vol-7-The-Young-Lions-Tournament-Hikaru-no-Go-7-by-Yumi-Hotta.pdf
    • http://weisncio.myhome.cx/3627629627627624/Play-Poker-Like-the-Pros-The-greatest-poker-player-in-the-world-today-reveals-his-million-dollar-winning-strategies-to-the-most-popular-tournament-home-and-online-games-by-Phil-Hellmuth.pdf
    • http://weisncio.my