Malicious PDF — malware analysis report

Static analysis result for SHA-256 c99eea845575294c…

MALICIOUS

PDF

16.8 KB Created: 2020-03-10 11:35:29 +00:00 Authoring application: mPDF 5.7
MD5: ffcddb80163cca64e5021e281a06f137 SHA-1: d4128450644d49fafe57163ccc510c707964e9c8 SHA-256: c99eea845575294c64a5f544bf4a884ac711370b313f77e6eda1a8d6e530370f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, all pointing to the same domain 'ieuicufioao.myhome.cx'. This pattern is indicative of a link farm or a traffic-driving scheme, often used to distribute malware or phish for credentials. The heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external PDF links, with 'ieuicufioao.myhome.cx' identified as the dominant host. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1551552553555558/Legacy-Code-Legacy-Code-1-by-Autumn-Kalquist.pdf
    • http://ieuicufioao.myhome.cx/8552559550559559/The-Pharaohs-Code-Creating-a-Joyful-Life-and-a-Lasting-Legacy-by-Mohamed-Tohami.pdf
    • http://ieuicufioao.myhome.cx/1551550558555555550/The-Bar-Code-2-Book-Set-The-Bar-Code-Tattoo-and-The-Bar-Code-Rebellion-by-Suzanne-Weyn.pdf
    • http://ieuicufioao.myhome.cx/2552551556556559/Code-Talker-The-First-and-Only-Memoir-By-One-of-the-Original-Navajo-Code-Talkers-of-WWII-by-Chester-Nez.pdf
    • http://ieuicufioao.myhome.cx/8559552553558556/How-to-Code-a-Sandcastle-How-to-Code-with-Pearl-amp-Pascal-1-by-Josh-Funk.pdf
    • http://ieuicufioao.myhome.cx/1558551555554552/Code-Name-Nanny-SEAL-and-Code-Name-5-by-Christina-Skye.pdf
    • http://ieuicufioao.myhome.cx/4556556556557559/A-Code-of-the-Heart-Code-Breakers-3-by-Jacki-Delecki.pdf
    • http://ieuicufioao.myhome.cx/8552553552556/Code-Name-Bikini-SEAL-and-Code-Name-9-by-Christina-Skye.pdf
    • http://ieuicufioao.myhome.cx/3559556550556557/Code-Name-Bundle-Includes-Code-Name-3-5-by-Christina-Skye.pdf
    • http://ieuicufioao.myhome.cx/1555557551556557/The-Stone-House-Legacy-Legacy-Trilogy-1-by-Wanda-Dehaven-Pyle.pdf
    • http://ieuicufioao.myhome.cx/4558554556554551/The-Stone-House-Legacy-Legacy-Trilogy-1-by-Wanda-Dehaven-Pyle.pdf
    • http://ieuicufioao.myhome.cx/1556558551555558/Carlotta-s-Legacy-Legacy-2-by-Betty-Thomason-Owens.pdf
    • http://ieuicufioao.myhome.cx/1556558553557551/Amelia-s-Legacy-Legacy-1-by-Betty-Thomason-Owens.pdf
    • http://ieuicufioao.myhome.cx/4559551551554553/Amelia-s-Legacy-Legacy-1-by-Betty-Thomason-Owens.pdf
    • http://ieuicufioao.myhome.cx/2552551553555555/The-Legacy-of-Kilkenny-The-Legacy-1-by-Devyn-Dawson.pdf
    • http://ieuicufioao.myhome.cx/1550550551551554/The-Wyndham-Legacy-Legacy-1-by-Catherine-Coulter.pdf
    • http://ieuicufioao.myhome.cx/1550554554555/Code-Name-Verity-Code-Name-Verity-1-by-Elizabeth-E-Wein.pdf
    • http://ieuicufioao.myhome.cx/6555552553552/Code-Name-Verity-Code-Name-Verity-1-by-Elizabeth-E-Wein.pdf
    • http://ieuicufioao.myhome.cx/4550556551553555/Code-of-the-Lifemaker-Code-of-the-Lifemaker-1-by-James-P-Hogan.pdf
    • http://ieuicufioao.myhome.cx/5550554550551556/Code-Breaker-Vol-01-Code-Breaker-1-by-Akimine-Kamijyo.pdf
    • http://ieuicufioao.myhome.cx/4556556556557559/A-Code