Malicious PDF — malware analysis report

Static analysis result for SHA-256 91be207a83e47e57…

MALICIOUS

PDF

23.0 KB Created: 2020-02-14 19:24:45 +00:00 Authoring application: mPDF 5.7
MD5: 7ed4288f86ab7e78445197904ed5a3c3 SHA-1: 1c6c7c2697df7a01d83f5870bfe4ccc4dc81ad5c SHA-256: 91be207a83e47e57b843b2a091e4c5896f3f6b0ab037aaffb88ba174691f52a6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs pointing to a single suspicious domain, indicative of a link farm or SEO poisoning attempt. The heuristic 'PDF_SEO_LINK_FARM' confirms this, identifying 27 external PDF links. The document body, though heavily obfuscated, also contains these URLs. The primary goal appears to be directing users to external content, potentially for malicious purposes such as malware distribution or phishing.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/1840849844840840848/Focus-On-100-Most-Popular-Fictional-Adoptees-Jessica-Jones-Iron-Man-Princess-Leia-Quicksilver-comics-Havok-comics-Jon-Snow-character-Uhtred-Krueger-Rogue-comics-Hellboy-etc-by-Wikipedia-contributors.pdf
    • http://easckaolp.myhome.cx/6845843845844/Donald-Duck-Comics-Donald-Duck-Comics-by-Carl-Barks-Donald-Duck-Comics-by-Don-Rosa-the-Life-and-Times-of-Scrooge-McDuck-by-Source-Wikipedia.pdf
    • http://easckaolp.myhome.cx/6844846841841842/Secret-Comics-Japan-Underground-Comics-Now-by-Hyoe-Narita.pdf
    • http://easckaolp.myhome.cx/9840840847841/The-Complete-Crumb-Comics-Vol-2-Some-More-Early-Years-of-Bitter-Struggle-by-Robert-Crumb.pdf
    • http://easckaolp.myhome.cx/4844842848844849/The-Complete-Crumb-Comics-Vol-4-Mr-Sixties-by-Robert-Crumb.pdf
    • http://easckaolp.myhome.cx/7845847841841845/Toronto-Comics-Anthology-Toronto-Comics-1-by-Steven-Andrews.pdf
    • http://easckaolp.myhome.cx/9842842841842843/Archie-1000-Page-Comics-Digest-by-Archie-Comics.pdf
    • http://easckaolp.myhome.cx/1840845844847849849/Comics-Squad-2-Lunch-Comics-Squad-2-by-Matthew-Holm.pdf
    • http://easckaolp.myhome.cx/7845847841845842/Toronto-Comics-Volume-3-Toronto-Comics-3-by-Steven-Andrews.pdf
    • http://easckaolp.myhome.cx/6846841842840844/Articles-on-French-Comics-Writers-Including-Ren-Goscinny-Enki-Bilal-Jacques-Tardi-Alejandro-Jodorowsky-Sylvain-Chomet-Joann-Sfar-Jacques-Martin-Comics-Fran-OIS-Bourgeon-Emmanuel-Larcenet-David-Beauchard-Lewis-Trondheim-by-Hephaestus-Books.pdf
    • http://easckaolp.myhome.cx/9840845842840/The-Best-of-Archie-Comics-Volume-2-by-Archie-Comics.pdf
    • http://easckaolp.myhome.cx/9843845840/The-Beatles-in-Comics-by-Gaet-39-s.pdf
    • http://easckaolp.myhome.cx/2844841845848/Eat-More-Comics-The-Best-of-the-Nib-by-Matt-Bors.pdf
    • http://easckaolp.myhome.cx/1846841848843840/Origins-of-Marvel-Comics-by-Stan-Lee.pdf
    • http://easckaolp.myhome.cx/2843848845846/Reading-Comics-by-Douglas-Wolk.pdf
    • http://easckaolp.myhome.cx/1849843845845847/DC-Comics-Bombshells-1-by-Marguerite-Bennett.pdf
    • http://easckaolp.myhome.cx/4846841842846842/The-Matrix-Comics-Vol-2-by-Lana-Wachowski.pdf
    • http://easckaolp.myhome.cx/9843846847843841/Comics-Versus-Art-by-Bart-Beaty.pdf
    • http://easckaolp.myhome.cx/4840849844842842/America-at-War-The-Best-of-DC-War-Comics-by-Michael-E-Uslan.pdf
    • http://easckaolp.myhome.cx/3849848848845840/Underworld-Vol-1-Cruel-and-Unusual-Comics-by-Kaz.pdf