Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b04c84196f0c733…

MALICIOUS

PDF

17.5 KB Created: 2020-03-18 21:08:38 +00:00 Authoring application: mPDF 5.7
MD5: 7249be18010c63f36cf26a24f3b25c47 SHA-1: 08bc6e8d25e3f7ec9a4e21f625cdae5af43c2e6d SHA-256: 4b04c84196f0c733126e99a8461a84c5e604b6af614417d62caecd8deb44b937
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, predominantly hosted on the domain 'ieuicufioao.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. No scripts were extracted from this sample, and the document body was unreadable, limiting the analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/4557555558553552/Alan-Turing-The-Enigma-by-Andrew-Hodges.pdf
    • http://ieuicufioao.myhome.cx/3554553555551555/Alan-Turing-The-Enigma-by-Andrew-Hodges.pdf
    • http://ieuicufioao.myhome.cx/7555558557555552/Alan-Turing-The-Enigma-Man-by-Nigel-Cawthorne.pdf
    • http://ieuicufioao.myhome.cx/2559552553552552/The-Man-Who-Knew-Too-Much-Alan-Turing-and-the-Invention-of-the-Computer-by-David-Leavitt.pdf
    • http://ieuicufioao.myhome.cx/4558558550559554/The-Man-Who-Knew-Too-Much-Alan-Turing-and-the-Invention-of-the-Computer-by-David-Leavitt.pdf
    • http://ieuicufioao.myhome.cx/4554553557557554/The-Case-of-Alan-Turing-The-Extraordinary-and-Tragic-Story-of-the-Legendary-Codebreaker-by-ric-Liberge.pdf
    • http://ieuicufioao.myhome.cx/7555558558558559/Lost-Languages-The-Enigma-of-the-World-s-Undeciphered-Scripts-by-Andrew-Robinson.pdf
    • http://ieuicufioao.myhome.cx/7555558555554557/Enigma-of-Life-Enigma-1-by-Shandi-Boyes.pdf
    • http://ieuicufioao.myhome.cx/5552551551557553/Trojan-Andrew-Harvey-1-by-Alan-McDermott.pdf
    • http://ieuicufioao.myhome.cx/2558558550555/Enigma-Black-Enigma-Black-1-by-Sara-Furlong-Burr.pdf
    • http://ieuicufioao.myhome.cx/1551556552551557553/Taran-by-Lisa-Hodges.pdf
    • http://ieuicufioao.myhome.cx/3555556550558559/Turing-Test-AI-Diaries-1-by-E-M-Foner.pdf
    • http://ieuicufioao.myhome.cx/2553558554554552/What-s-For-Lunch-Charley-by-Margaret-Hodges.pdf
    • http://ieuicufioao.myhome.cx/5554552554552/His-Sexy-Bad-Habit-by-Cheris-Hodges.pdf
    • http://ieuicufioao.myhome.cx/4559556557552558/Joshua-s-Island-by-Patrick-Hodges.pdf
    • http://ieuicufioao.myhome.cx/2555558559558551/Thinking-on-the-Web-Berners-Lee-G-del-and-Turing-by-H-Peter-Alesso.pdf
    • http://ieuicufioao.myhome.cx/6559558556557/Saint-George-and-the-Dragon-by-Margaret-Hodges.pdf
    • http://ieuicufioao.myhome.cx/6552552558557558/The-Doctor-Who-Annual-1974-by-Edgar-Hodges.pdf
    • http://ieuicufioao.myhome.cx/8551551555550/A-Madman-Dreams-of-Turing-Machines-by-Janna-Levin.pdf
    • http://ieuicufioao.myhome.cx/1551557558553558555/The-New-Turing-Omnibus-66-Excursions-In-Computer-Science-by-A-K-Dewdney.pdf
    • http://ieuicufio