Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3ec217348604545…

MALICIOUS

PDF

20.8 KB Created: 2020-03-18 22:24:05 +00:00 Authoring application: mPDF 5.7
MD5: 86c41f5ef16b9f22f912dc73ab677c3b SHA-1: 097ec86d513a6048437611d1eb4552a9899df556 SHA-256: b3ec217348604545c1633bb0affaf52f5dfa46cfe8d0f2bfd102ed4c2b6787ed
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with 27 external PDF links embedded. The dominant host for these links is 'ieuicufioao.myhome.cx'. The embedded links likely serve as a lure to redirect users to malicious content or phishing pages. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/9557555550557550/Pattern-recognition-by-M-M-Bongard.pdf
    • http://ieuicufioao.myhome.cx/2556557553554/Pattern-Recognition-Blue-Ant-1-by-William-Gibson.pdf
    • http://ieuicufioao.myhome.cx/9552556557552558/Markov-Models-for-Pattern-Recognition-From-Theory-to-Applications-by-Gernot-A-Fink.pdf
    • http://ieuicufioao.myhome.cx/9552556555557557/Markov-Models-For-Pattern-Recognition-From-Theory-To-Applications-by-Gernot-A-Fink.pdf
    • http://ieuicufioao.myhome.cx/1550551551550556551/Structural-Pattern-Recognition-with-Graph-Edit-Distance-Approximation-Algorithms-and-Applications-by-Kaspar-Riesen.pdf
    • http://ieuicufioao.myhome.cx/9557555552550551/Nobody-Ever-Wins-A-War-The-World-War-I-Diaries-Of-Ella-Mae-Bongard-R-N-by-Ella-Mae-Bongard.pdf
    • http://ieuicufioao.myhome.cx/9557555551553556/Loving-one-more-by-Katrin-Bongard.pdf
    • http://ieuicufioao.myhome.cx/9557555551553557/Crazy-Summer-by-Katrin-Bongard.pdf
    • http://ieuicufioao.myhome.cx/9557555552550556/The-Catcher-by-Katrin-Bongard-Uwe-Carow.pdf
    • http://ieuicufioao.myhome.cx/9557555552550550/Tweaks-How-to-Fix-and-Fine-Tune-Your-Volunteer-Organization-by-Tim-Bongard.pdf
    • http://ieuicufioao.myhome.cx/9557555551554553/Reise-amp-Reportage-Die-Fotoschule-f-r-die-Bilder-die-Geschichten-erz-hlen-by-Peter-Bongard.pdf
    • http://ieuicufioao.myhome.cx/3556558551551553/Recognition-Liberty-First-1-by-Marc-Moore.pdf
    • http://ieuicufioao.myhome.cx/9552559557551552/Beyond-Recognition-Boldt-Matthews-4-by-Ridley-Pearson.pdf
    • http://ieuicufioao.myhome.cx/1551558554550553554/The-Recognition-of-Shakuntala-Kashmir-Recension-by-K-lid-sa.pdf
    • http://ieuicufioao.myhome.cx/6551551554558552/Marie-NDiaye-Blankness-and-Recognition-by-Andrew-Asibong.pdf
    • http://ieuicufioao.myhome.cx/8550555551554558/Jane-s-Airline-Recognition-Guide-by-G-nter-G-Endres.pdf
    • http://ieuicufioao.myhome.cx/7556555559557559/Computer-Recognition-and-Human-Production-of-Handwriting-by-R-Plamondon.pdf
    • http://ieuicufioao.myhome.cx/7557558559559550/Laplace-Spectra-for-Shape-Recognition-by-Martin-Reuter.pdf
    • http://ieuicufioao.myhome.cx/7556557551553556/Law-Labour-and-Society-in-Japan-From-Repression-to-Reluctant-Recognition-by-Anthony-Woodiwiss.pdf
    • http://ieuicufioao.myhome.cx/7551550553555558/The-Carrot-Principle-How-the-Best-Managers-Use-Recognition-to-Engage-Their-Employees-Retain-Talent-and-Drive-Performance-by-Adrian-Gostick.pdf
    • http://ieuicufioao.myhome.cx/9557555552550551/Nobody-Ever