Malicious PDF — malware analysis report

Static analysis result for SHA-256 469aa2d27b942429…

MALICIOUS

PDF

26.1 KB Created: 2020-03-18 21:51:51 +00:00 Authoring application: mPDF 5.7
MD5: 6371ee47785bfd7959c3ca2b3a4c90c3 SHA-1: bd752dde8a057124ff53ed5b90a70384800c475b SHA-256: 469aa2d27b94242944514f3eee494fa7b4a69a9896c76b7e5f05f5bd8a3b01d8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a significant number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external PDF documents hosted on a suspicious domain, suggesting a link farm or SEO poisoning tactic. The document body itself is heavily obfuscated and does not provide clear user-facing content, further indicating a malicious intent to redirect users to potentially harmful sites.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1550553554558554556/Bahnhof-in-Berlin-Bahnhof-Berlin-Zoologischer-Garten-Bahnhof-Berlin-Lichtenberg-Berlin-Hauptbahnhof-Liste-Der-Bahnhofe-Im-Raum-Berlin-by-Books-LLC.pdf
    • http://ieuicufioao.myhome.cx/1550551553555553552/Ort-in-Berlin-Berlin-Schoneberg-Liste-Der-Bezirke-Und-Ortsteile-Berlins-Berlin-Kreuzberg-Bezirk-Tempelhof-Schoneberg-Berlin-Temp-by-Quelle-Wikipedia.pdf
    • http://ieuicufioao.myhome.cx/2556554550554554/The-Toymaker-by-Liam-Pieper.pdf
    • http://ieuicufioao.myhome.cx/1550552555557553556/New-National-Gallery-Berlin-Berlin-1962-68-Ludwig-Mies-Van-Der-Rohe-by-Maritz-Vandenberg.pdf
    • http://ieuicufioao.myhome.cx/3554553554550559/The-Berlin-Stories-The-Last-of-Mr-Norris-amp-Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://ieuicufioao.myhome.cx/1551555551559551552/Berlin-auf-die-Schnelle-Schlaglichter-Berlin-2015-by-Daniel-A-Kempken.pdf
    • http://ieuicufioao.myhome.cx/1558550556552/Smart-Love-The-Comprehensive-Guide-to-Understanding-Regulating-and-Enjoying-Your-Child-by-Martha-Heineman-Pieper.pdf
    • http://ieuicufioao.myhome.cx/9550558555559557/Dem-Kelch-Zuliebe-Exulant-250-Jahre-Bohmisches-Dorf-in-Berlin-Neukolln-Begleitband-Zur-Ausstellung-17-Mai-9-August-1987-Galerie-Im-Kornerpar-by-Bezirksamt-Neuk-Olln-Von-Berlin.pdf
    • http://ieuicufioao.myhome.cx/9551557558551556/Flaneure-in-Berlin-Und-Frankfurt-Am-Main-Urbane-Muigganger-in--Spazieren-in-Berlin--Und--Tarzan-Am-Main--by-Nelly-Bachmann.pdf
    • http://ieuicufioao.myhome.cx/9553558554554552/BERLIN-GERMAN-TRAVEL-PHRASES-FOR-ENGLISH-SPEAKERS-The-most-useful-1-000-phrases-to-get-around-when-travelling-in-Berlin-by-Sarah-Retter.pdf
    • http://ieuicufioao.myhome.cx/1550557550559553551/K-nigliche-Schl-sser-in-Berlin-und-Brandenburg-Royal-palaces-in-Berlin-and-Brandenburg-by-Hans-Joachim-Giersberg.pdf
    • http://ieuicufioao.myhome.cx/1551555558556552556/Erst-mal-49-werden-by-Mira-Steffan.pdf
    • http://ieuicufioao.myhome.cx/1551555558558553552/Das-ist-erst-der-Anfang-Kurzroman-by-E-M-M-A-Walker.pdf
    • http://ieuicufioao.myhome.cx/1551555558558552558/Der-Pramienzahlungsverzug-Bei-Erst--Und-Folgepramie-by-Andreas-Riedler.pdf
    • http://ieuicufioao.myhome.cx/1551555558559550558/Besser-leben-Ego-ist-Immer-erst-Ich-by-Christopher-Ray.pdf
    • http://ieuicufioao.myhome.cx/1551555558557550555/Erst-mal-f-r-immer-Kreta-by-Helena-Baum.pdf
    • http://ieuicufioao.myhome.cx/1551555558556551558/Electronics-Equations-Handbook-by-Steven-J-Erst.pdf
    • http://ieuicufioao.myhome.cx/1551555558557550551/Rebirth-der-Tod-ist-erst-der-Anfang-by-Edgar-Wiefel.pdf
    • http://ieuicufioao.myhome.cx/1551555558559551550/Erst-die-Ehe-dann-das-Vergn-gen-Roman-by-Nelly-Arnold.pdf
    • http://ieuicufioao.myhome.cx/1551555558559550550/Auswandern-in-die-Schweiz---Jetzt-erst-recht-by-Peter-Hoffmann.pdf