Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ce018deadfa9e67…

MALICIOUS

PDF

18.4 KB Created: 2020-02-16 04:00:27 +00:00 Authoring application: mPDF 5.7
MD5: 4da05b6550cb0e5f55c2ab82d3587ac1 SHA-1: 2abccf3660b18149a53029ef08dd75e686e88ec1 SHA-256: 8ce018deadfa9e6736e226d13d6ef55658697d7adcccc4440eca3183249f13e9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to a single domain, 'ieuicufioao.myhome.cx'. This pattern is indicative of a link farm designed to distribute malicious content or engage in SEO abuse. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior, identifying 24 external PDF links. The document body, though heavily obfuscated, also contains these URLs, reinforcing the attack pattern.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/6550551554559557/Hippolyte-and-Golden-Beak-by-George-Bassett.pdf
    • http://ieuicufioao.myhome.cx/4552556559559551/When-the-Game-Changed-An-Oral-History-of-Baseball-s-True-Golden-Age-1969--1979-by-George-Castle.pdf
    • http://ieuicufioao.myhome.cx/8552553553555/The-Man-With-the-Golden-Gun-James-Bond-13-by-Ian-Fleming.pdf
    • http://ieuicufioao.myhome.cx/1555550552556557/The-Golden-Table-by-James-Oliver.pdf
    • http://ieuicufioao.myhome.cx/5554553556557/The-Golden-Moonbeam-by-Angela-James.pdf
    • http://ieuicufioao.myhome.cx/1558558552550558/The-Golden-Chain-by-Margaret-James.pdf
    • http://ieuicufioao.myhome.cx/6552556552551554/Golden-Age-The-Shifting-Tides-1-by-James-Maxwell.pdf
    • http://ieuicufioao.myhome.cx/4559556558559555/The-Golden-Cage-The-Ballad-of-Sir-Benfro-3-by-James-Oswald.pdf
    • http://ieuicufioao.myhome.cx/3555551554558/Californians-Searching-for-the-Golden-State-by-James-D-Houston.pdf
    • http://ieuicufioao.myhome.cx/2556551551559559/Gastroanomalies-Questionable-Culinary-Creations-from-the-Golden-Age-of-American-Cookery-by-James-Lileks.pdf
    • http://ieuicufioao.myhome.cx/8552559555550/Apple-Bough-by-Noel-Streatfeild.pdf
    • http://ieuicufioao.myhome.cx/9555553552550553/The-Bough-That-Will-Not-Break-by-Tancre-Bonnie.pdf
    • http://ieuicufioao.myhome.cx/9553557555553552/Cast-of-Characters-Wolcott-Gibbs-E-B-White-James-Thurber-and-the-Golden-Age-of-The-New-Yorker-by-Thomas-Vinciguerra.pdf
    • http://ieuicufioao.myhome.cx/2553552556553557/Green-Bough-of-Liberty-by-David-Rees.pdf
    • http://ieuicufioao.myhome.cx/3552553557551558/Murder-under-the-Kissing-Bough-Auguste-Didier-6-by-Amy-Myers.pdf
    • http://ieuicufioao.myhome.cx/1550551550550558/Stolen-Legacy-by-George-G-M-James.pdf
    • http://ieuicufioao.myhome.cx/8555550557550558/When-the-Bough-Breaks-Pregnancy-and-the-Legacy-of-Addiction-by-Kira-Corser.pdf
    • http://ieuicufioao.myhome.cx/1550552550551554553/Marble-Faun-and-a-Green-Bough-Poems-by-William-Faulkner.pdf
    • http://ieuicufioao.myhome.cx/3551553553556551/George-and-Martha-One-Fine-Day-by-James-Marshall.pdf
    • http://ieuicufioao.myhome.cx/4552556557554555/Jesse-James-and-the-Lost-Templar-Treasure-Secret-Diaries-Coded-Maps-and-the-Knights-of-the-Golden-Circle-by-Daniel-J-Duke.pdf
    • http://ieuicufioao.myhome.cx/2556551551559559/Gastroanomalies-Questionable-Culinary-Creations-from-the-Golden-Age-o