Malicious PDF — malware analysis report

Static analysis result for SHA-256 94ba1e1cab5b085a…

MALICIOUS

PDF

20.3 KB Created: 2020-02-05 10:04:55 +00:00 Authoring application: mPDF 5.7
MD5: fe25674fae7390d31bcef5fa5eb27e0b SHA-1: a62fa6158c0f2c1c38549557aeb2d1ca98597b0d SHA-256: 94ba1e1cab5b085af327965ce0135afb50bbcc17f26f375a5a4340d400da6ef7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a heuristic firing for a large number of external links, with the first URL being http://ieuicufioao.myhome.cx/2553558555550555/The-Elements-of-Typographic-Style-Version-4-0-by-Robert-Bringhurst.pdf. This suggests a link farm or a method to redirect users to potentially malicious content. The document body was not sufficiently readable to provide further context on its specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2553558555550555/The-Elements-of-Typographic-Style-Version-4-0-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/1551556555559555557/The-Elements-of-Style-by-William-Strunk-Jr-.pdf
    • http://ieuicufioao.myhome.cx/4555555550551557/The-Periodic-Table-Elements-with-Style-by-Simon-Basher.pdf
    • http://ieuicufioao.myhome.cx/1556557554550552/The-Tree-Of-Meaning-Thirteen-Talks-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/1552550558558555/Everywhere-Being-Is-Dancing-Twenty-Pieces-of-Thinking-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/1554551558550550/Being-in-Being-The-Collected-Works-of-Skaay-of-the-Qquuna-Qiighawaay-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/8555551555550553/The-Elements-of-Style-The-Original-Manual-of-Writing-and-Composition-by-William-Strunk-Jr-.pdf
    • http://ieuicufioao.myhome.cx/1552558557552553/Ursa-Major-A-Polyphonic-Masque-for-Speakers-amp-Dancers-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/8552552551557551/The-Elements-of-Style-Illustrated-Formatted-version-with-illustrations-for-each-topic-by-William-Strunk-Jr-.pdf
    • http://ieuicufioao.myhome.cx/1554554555555558/A-Story-as-Sharp-as-a-Knife-The-Classical-Haida-Mythtellers-and-Their-World-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/1553550550555555/The-Black-Canoe-Bill-Reid-and-the-Spirit-of-Haida-Gwaii-by-Robert-Bringhurst.pdf
    • http://ieuicufioao.myhome.cx/1551550554552554556/The-Elements-of-Style-by-William-Strunk-The-Elements-of-Style-by-William-Strunk-by-William-Strunk.pdf
    • http://ieuicufioao.myhome.cx/9551552550550553/Elements-of-Ecology-by-Robert-Leo-Smith.pdf
    • http://ieuicufioao.myhome.cx/1559551556556557/Albert-Camus-Elements-of-a-Life-by-Robert-Zaretsky.pdf
    • http://ieuicufioao.myhome.cx/6559551552557550/Andrei-Tarkovsky-Elements-of-Cinema-by-Robert-C-Bird.pdf
    • http://ieuicufioao.myhome.cx/9559555555559551/American-Bungalow-Style-by-Robert-Winter.pdf
    • http://ieuicufioao.myhome.cx/1550559553557550557/Photographic-Card-Deck-of-The-Elements-With-Big-Beautiful-Photographs-of-All-118-Elements-in-the-Periodic-Table-by-Theodore-Gray.pdf
    • http://ieuicufioao.myhome.cx/5555552559553559/Joie-de-Vivre-Simple-French-Style-for-Everyday-Living-by-Robert-Arbor.pdf
    • http://ieuicufioao.myhome.cx/2550557554550550/Broken-Elements-Elements-1-by-Mia-Marshall.pdf
    • http://ieuicufioao.myhome.cx/9551551557555557/Broken-Elements-Elements-1-by-Mia-Marshall.pdf
    • http://ieuicufioao.myhome.cx/1552558557552553/Ursa-Major-A-Polyphonic-Masqu