Malicious PDF — malware analysis report

Static analysis result for SHA-256 8129e6e0036cb88f…

MALICIOUS

PDF

21.5 KB Created: 2020-03-20 00:40:28 +00:00 Authoring application: mPDF 5.7
MD5: 5c4baf83f0305d8e661d0c9923032522 SHA-1: cdbd92c555b015f057be15f0d43615e41273d7fe SHA-256: 8129e6e0036cb88f8716fb8e981dbc72e45a1719acf079f5061fe13f8098194e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a mass of embedded links pointing to a single, suspicious domain, indicating a link farm or redirection scheme. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this is an attempt to drive traffic to potentially malicious content. No scripts were extracted from this sample, limiting further analysis of its direct actions.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1550557558556552559/Tiger---streak-free-Bilingual-bicolored-short-short-story-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556554553/Kurze-Kurzgeschichten-AmE-Short-short-stories-AmE-Kurze-Kurzgeschichten-AmE-zweisprachig-1-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/2557557551559556/Vampire-Mansion-A-Short-Story-by-Alexis-Tiger.pdf
    • http://ieuicufioao.myhome.cx/3551553557551555/Short-Stories-for-Early-Readers-17-Stories-in-1-Fairy-Tales-Kids-Story-Bundle-Childrens-ebooks-Short-Story-Series-Diaries-of-Simple-Reading-by-Betty-J-Byers.pdf
    • http://ieuicufioao.myhome.cx/5554551556557557/Mismatched-Metacarpi-Short-Stories-by-New-Nottingham-Writers-Comma-Short-Story-Course-7-by-Andy-Hedgecock.pdf
    • http://ieuicufioao.myhome.cx/7551550552553551/The-Summer-Vacation-A-Short-Horror-Story-Short-Stories-Book-1-by-Taiden-Dashner-Gabaldon.pdf
    • http://ieuicufioao.myhome.cx/2559555559552551/The-Best-American-Short-Stories-1954-and-the-Yearbook-of-the-American-Short-Story-by-Martha-Foley.pdf
    • http://ieuicufioao.myhome.cx/1550557558556553553/Eis-br-echer-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558555559554/The-Big-Shot-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556559552/9-Kurze-2011-zweisprachiges-eBuch-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556557556/Pop-meets-Classic--Pop-trifft-Klassik-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556558556/The-Fact-dual-language-ebook-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556554550/Der-Gro-e-Wurf-Kurze-Kurzgeschichte-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558557552551/The-Big-Melt---A-Musical-Play-Complete-edition-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556554555/Funkelnde-Augen-im-st-rmenden-Wald-zweisprachiges-eBuch-7-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556550552/Euklids-Erweiterung-des-Lehrsatzes-von-Pythagoras---zweisprachige-Ausgabe-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558555551550/Solar-Power---Plants-and-Charts-dual-language-e-books-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/1550557558556550555/Sparkling-Eyes-in-the-Stormy-Forest-dual-language-ebook-by-Jutta-Mahlke.pdf
    • http://ieuicufioao.myhome.cx/3552557552559553/Flash-Fiction-Addiction-22-Short-Short-Stories-Volume-III-by-Garden-Summerland.pdf
    • http://ieuicufioao.myhome.cx/4550555554553557/You-Have-Time-for-This-Contemporary-American-Short-Short-Stories-by-Mark-Budman.pdf
    • http://ieuicufioao.myhome.cx/5554551556557557/Mismatched-Metacarpi-Short-Stories-by-New-Nottingham-Writers-Comma-Short-St