Malicious PDF — malware analysis report

Static analysis result for SHA-256 a36b24dfd593a05f…

MALICIOUS

PDF

17.9 KB Created: 2020-02-09 23:00:37 +00:00 Authoring application: mPDF 5.7
MD5: 6126bd68659241e86606a63e2903c143 SHA-1: a72e314107e6c4abfdff217ff9b189cf638a87b3 SHA-256: a36b24dfd593a05f8ed028df26a306bfb57ea9160a3792d21b7243b0090edd0e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, all pointing to the same domain, 'ieuicufioao.myhome.cx'. This suggests a link farm or a method to distribute malicious content disguised as legitimate documents. The heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external PDF links, with the primary URL being http://ieuicufioao.myhome.cx/3551552552550550/An-Exaltation-of-Larks-The-Ultimate-Edition-by-James-Lipton.pdf. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/3551552552550550/An-Exaltation-of-Larks-The-Ultimate-Edition-by-James-Lipton.pdf
    • http://ieuicufioao.myhome.cx/2555558558555551/An-Exaltation-of-Larks-The-Ultimate-Edition-by-James-Lipton.pdf
    • http://ieuicufioao.myhome.cx/8557552559553550/An-Exaltation-of-Larks-by-Robert-Reed.pdf
    • http://ieuicufioao.myhome.cx/8557552559556559/An-Exaltation-of-Larks-by-Megan-Hart.pdf
    • http://ieuicufioao.myhome.cx/2553550553556550/Inside-Inside-by-James-Lipton.pdf
    • http://ieuicufioao.myhome.cx/9554556551558556/Battle-Royale-Ultimate-Edition-Volume-3-by-Koushun-Takami.pdf
    • http://ieuicufioao.myhome.cx/9558551558559558/The-Angel-Chronicles-2nd-Edition-Volume-4-The-Ultimate-Betrayal-by-Lanze-Thompson.pdf
    • http://ieuicufioao.myhome.cx/8557552559553557/The-Larks-by-Jem-Shaw.pdf
    • http://ieuicufioao.myhome.cx/2550553553557559/The-Greek-s-Ultimate-Revenge-by-Julia-James.pdf
    • http://ieuicufioao.myhome.cx/8550550550553557/The-Gun-Owner-s-Bible-The-Ultimate-Guide-by-James-Darnell.pdf
    • http://ieuicufioao.myhome.cx/6558553557559554/Alias-Olympia-by-Eunice-Lipton.pdf
    • http://ieuicufioao.myhome.cx/9558555552556552/Ulysses-by-James-Joyce-Illustrated-Delphi-Parts-Edition-James-Joyce-by-James-Joyce.pdf
    • http://ieuicufioao.myhome.cx/6553554557557551/The-Ultimate-Londoner-John-Mordred-Book-9-by-James-Ward.pdf
    • http://ieuicufioao.myhome.cx/1558559557553556/How-Jesus-Became-God-The-Exaltation-of-a-Jewish-Preacher-from-Galilee-by-Bart-D-Ehrman.pdf
    • http://ieuicufioao.myhome.cx/6558557551554/The-Wisdom-of-Your-Cells-How-Your-Beliefs-Control-Your-Biology-by-Bruce-H-Lipton.pdf
    • http://ieuicufioao.myhome.cx/2553554551552551/Boxed-Set-Older-and-Younger-Ultimate-Gay-Bundle-Gay-Contemporary-Romance-Best-First-Time-by-James-Benedict-Noble.pdf
    • http://ieuicufioao.myhome.cx/3551555557558558/Ultimate-Kill-Ultimate-CORE-1-by-Kristine-Mason.pdf
    • http://ieuicufioao.myhome.cx/1550558554556551552/Ultimate-X-Men-Volume-5-Ultimate-War-by-Mark-Millar.pdf
    • http://ieuicufioao.myhome.cx/1558554557559555/The-Ultimate-Gift-and-the-Ultimate-Life-by-Jim-Stovall.pdf
    • http://ieuicufioao.myhome.cx/6550555551559555/Gens-de-Dublin-dition-int-grale-by-James-Joyce.pdf