Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb9d6f125cb947ae…

MALICIOUS

PDF

17.9 KB Created: 2020-03-15 10:26:55 +00:00 Authoring application: mPDF 5.7
MD5: 4320b18640ecf04e59593e42592df807 SHA-1: ff8f807614981883b9585d8c328d7658abcdd393 SHA-256: cb9d6f125cb947ae6ddf33795c76353c0e7f381297af43d217b0813d96cdc2d2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, with 25 numeric slug SEO PDF links. The URLs themselves are hosted on a suspicious domain, 'kitasdyu.myhome.cx', suggesting a potential distribution or phishing campaign. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/2877878877873870/The-Hammer-of-the-Sun-The-Winter-of-the-World-3-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/5874873875877/The-Anvil-of-Ice-The-Winter-of-the-World-1-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/4877879871875872/The-Castle-of-the-Winds-The-Winter-of-the-World-4-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/8874876872877879/Michael-Scott-The-Secrets-of-the-Immortal-Nicholas-Flamel-6-Books-Collection-by-Michael-Scott.pdf
    • http://kitasdyu.myhome.cx/4870872879879870/Deeper-Hammer-21-by-Sean-Michael.pdf
    • http://kitasdyu.myhome.cx/4870872879877879/Treat-A-Hammer-Story-by-Sean-Michael.pdf
    • http://kitasdyu.myhome.cx/3872877874874870/A-Long-Time-Dead-A-Mike-Hammer-Casebook-Mike-Hammer-Novels-by-Mickey-Spillane.pdf
    • http://kitasdyu.myhome.cx/6871872878877878/Scott-Im-Interpersonal-Commun-by-Michael-D-Scott.pdf
    • http://kitasdyu.myhome.cx/1878870878879875/The-Fourteen-Bears-in-Summer-and-Winter-by-Evelyn-F-Scott.pdf
    • http://kitasdyu.myhome.cx/1874871879873872/This-All-Happened-by-Michael-Winter.pdf
    • http://kitasdyu.myhome.cx/9879877872879/Architects-Are-Here-by-Michael-Winter.pdf
    • http://kitasdyu.myhome.cx/2871873878870870/Winter-s-Heart-by-Michael-Kanuckel.pdf
    • http://kitasdyu.myhome.cx/4870870873874878/The-World-According-to-Michael-An-Old-Soul-s-Guide-to-the-Universe-A-Michael-Book-by-Joya-Pope.pdf
    • http://kitasdyu.myhome.cx/4876878870872874/Winter-World-by-C-J-Mills.pdf
    • http://kitasdyu.myhome.cx/1878877872875878/The-Winter-Calf-Maple-Gap-1-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/1870878874877870/The-Winter-Calf-Maple-Gap-1-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/1876873872876876/Winter-of-the-World-Century-Trilogy-2-by-Ken-Follett.pdf
    • http://kitasdyu.myhome.cx/4874878872876871/Winter-of-the-World-The-Century-Trilogy-2-by-Ken-Follett.pdf
    • http://kitasdyu.myhome.cx/1877873875875871/Half-the-World-in-Winter-by-Maggie-Joel.pdf
    • http://kitasdyu.myhome.cx/3873878875875876/The-Disappearance-of-Winter-s-Daughter-The-Riyria-Chronicles-4-by-Michael-J-Sullivan.pdf