Malicious PDF — malware analysis report

Static analysis result for SHA-256 55af779704b7af90…

MALICIOUS

PDF

19.7 KB Created: 2020-03-13 22:10:39 +00:00 Authoring application: mPDF 5.7
MD5: 7c4f439d9f5283e77afe8127912bf41c SHA-1: 1f9f4df8f9da25d6bafbdc1fc7ed08074e133408 SHA-256: 55af779704b7af90ef02c99f2a94b376c6f66cc36da7de00d02ae58e311e31dd
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a single suspicious domain, indicating a link farm. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior. The embedded URLs are likely intended to lure users into downloading further malicious content or visiting malicious sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/6559555556556553/Carnivores-Handbook-of-the-Mammals-of-the-World-1-by-Don-E-Wilson.pdf
    • http://ieuicufioao.myhome.cx/8555550552559/The-Snowden-Files-The-Inside-Story-of-the-World-s-Most-Wanted-Man-by-Luke-Harding.pdf
    • http://ieuicufioao.myhome.cx/6553550558559/Richmond-Unchained-The-Biography-of-the-World-s-First-Black-Sporting-Superstar-by-Luke-G-Williams.pdf
    • http://ieuicufioao.myhome.cx/4550559550554558/Life-in-the-World-of-Yomo-Start-the-Adventure-to-Your-Perfect-Calling-by-Melissa-Luke.pdf
    • http://ieuicufioao.myhome.cx/2552550550551559/Luke-Complete-Series-Luke-1-7-by-Cassia-Leo.pdf
    • http://ieuicufioao.myhome.cx/1557556552552556/The-World-Keepers-Three-Book-Set-Roblox-Fantasy-The-World-Keepers-1-3-by-Ty-The-Hunter.pdf
    • http://ieuicufioao.myhome.cx/6559555555558551/Carnivores-by-J-R-Levitt.pdf
    • http://ieuicufioao.myhome.cx/8553555553556559/The-50-Most-Iconic-Photographs-Ever-Taken-The-50-Photographs-That-Changed-the-World-by-Luke-Dollard.pdf
    • http://ieuicufioao.myhome.cx/1557556552553553/The-World-Keepers-4-by-Ty-The-Hunter.pdf
    • http://ieuicufioao.myhome.cx/3558559554553/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://ieuicufioao.myhome.cx/6559555555553558/Carnivores-by-John-Levitt.pdf
    • http://ieuicufioao.myhome.cx/6559555555553556/Carnivores-by-Richard-Poche.pdf
    • http://ieuicufioao.myhome.cx/1550553554553558553/Das-M-dchen-und-der-Deserteur-Luke-Sinclair-Western-Band-27-by-Luke-Sinclair.pdf
    • http://ieuicufioao.myhome.cx/5557553555551556/The-Bronze-Blade-Elemental-World-2-5-by-Elizabeth-Hunter.pdf
    • http://ieuicufioao.myhome.cx/2553557555555559/A-Stone-Kissed-Sea-Elemental-World-4-by-Elizabeth-Hunter.pdf
    • http://ieuicufioao.myhome.cx/1551555551558554/Building-From-Ashes-Elemental-World-1-by-Elizabeth-Hunter.pdf
    • http://ieuicufioao.myhome.cx/3552554556554550/The-Scarlet-Deep-Elemental-World-3-by-Elizabeth-Hunter.pdf
    • http://ieuicufioao.myhome.cx/6559555556555558/The-Book-of-Steak-Cooking-for-Carnivores-by-Parragon-Publishing.pdf
    • http://ieuicufioao.myhome.cx/5555554559554557/Amped-The-Illustrated-History-of-the-World-s-Greatest-Amplifiers-by-Dave-Hunter.pdf
    • http://ieuicufioao.myhome.cx/2553557553550553/Virus-Hunter-Thirty-Years-of-Battling-Hot-Viruses-Around-the-World-by-C-J-Peters.pdf
    • http://ieuicufioao.myhome.cx/1557556552552556/The-World-Keepers-Three-Book-Set-Roblox-Fantasy-The-World-Keepers-1-3-by-Ty-The-Hunter