Malicious PDF — malware analysis report

Static analysis result for SHA-256 ceb95a64423d9233…

MALICIOUS

PDF

22.1 KB Created: 2020-03-18 21:25:18 +00:00 Authoring application: mPDF 5.7
MD5: 90ca0aabf6ec395959c8ac9fe2565e54 SHA-1: bd3a26a4f71c28c1f50ba05a2700303faf6b342f SHA-256: ceb95a64423d92335f2588c0648983fb197660f1e3e585619d41c31d3f9dab99
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged for containing a large number of external links, a technique often used for SEO poisoning or to redirect users to malicious websites. The heuristic 'PDF_SEO_LINK_FARM' specifically identified 27 such links, with the primary domain being solosopos.myhome.cx. No scripts were extracted from this sample. The attack pattern is consistent with a link-farming or redirection scheme designed to lure users to potentially harmful content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solosopos.myhome.cx/5857859850852853/Alain-Fournier-au-miroir-du-Grand-Meaulnes-by-Pierre-Suire.pdf
    • http://solosopos.myhome.cx/3855856859851/Le-Grand-Meaulnes-by-Alain-Fournier.pdf
    • http://solosopos.myhome.cx/5857859850851851/Le-Grand-Meaulnes-and-Miracles-by-Alain-Fournier.pdf
    • http://solosopos.myhome.cx/5857859850851852/Alain-Fournier-Romancier-Le-Grand-Meaulnes-by-Zbigniew-Naliwajek.pdf
    • http://solosopos.myhome.cx/5856855854859852/Le-grand-Meaulnes---Texte-abr-g-Jeunes-Adultes-by-Alain-Fournier.pdf
    • http://solosopos.myhome.cx/5857859850850855/The-great-Meaulnes-by-Alain-Fournier-Alain-Fournier.pdf
    • http://solosopos.myhome.cx/8857859850858855/The-Wanderer-by-Alain-Fournier.pdf
    • http://solosopos.myhome.cx/7858859855855859/Alain-Fournier-Destins-Inacheve-amp-X301-S-by-Patrick-Martinat.pdf
    • http://solosopos.myhome.cx/7852853856850859/Grand-Livre-De-Cuisine-Alain-Ducasse-s-Culinary-Encyclopedia-by-Alain-Ducasse.pdf
    • http://solosopos.myhome.cx/1851852856855854850/The-Rise-Of-The-French-Novel-Marivaux-Crb-illon-I-E-Crb-illon-Fils-Rousseau-Stendhal-Flaubert-Alain-Fournier-Raymond-Radiguet-by-Martin-Turnell.pdf
    • http://solosopos.myhome.cx/6859859858851859/Le-Grand-Refus-Reflexions-Sur-La-Greve-de-Decembre-1995-by-Alain-Touraine.pdf
    • http://solosopos.myhome.cx/7859859851851852/Atlas-of-Upper-Gastrointestinal-and-Hepato-Pancreato-Biliary-Surgery-by-Pierre-Alain-Clavien.pdf
    • http://solosopos.myhome.cx/7859859851850857/Atlas-of-Upper-Gastrointestinal-and-Hepato-Pancreato-Biliary-Surgery-by-Pierre-Alain-Clavien.pdf
    • http://solosopos.myhome.cx/6853858859851855/La-R-volution-tranquille-en-h-ritage-Selon-Jacques-Beauchemin-Alain-Dubuc-Lucia-Ferretti-Pierre-Fortin-Luc-Godbout-Monique-J-r-me-Forget-Yvan-Lamonde-et-Gilles-Paquet-by-Guy-Berthiaume.pdf
    • http://solosopos.myhome.cx/4851858857859852/Last-Year-at-Marienbad-Text-for-the-Film-by-Alain-Resnais-by-Alain-Robbe-Grillet.pdf
    • http://solosopos.myhome.cx/7858859851855853/caste-by-kyla-fournier-by-Kyla-Fournier.pdf
    • http://solosopos.myhome.cx/2851851857855/Seduction-of-an-English-Beauty-Grand-Passion-on-the-Grand-Tour-2-by-Miranda-Jarrett.pdf
    • http://solosopos.myhome.cx/6851853851851855/It-Was-Her-Tree-Chapter-5-of-THE-THIRD-RED-APPLE-VOL-1-by-Miroir-Mitani.pdf
    • http://solosopos.myhome.cx/6851855852856854/Un-Homme-Grand-Jack-Kerouac-at-the-Crossroads-of-Many-Cultures-Jack-Kerouac-a-la-Confluence-Des-Cultures-by-Pierre-Anctil.pdf
    • http://solosopos.myhome.cx/7858851852856856/Le-Verglas-Comme-Miroir-Roman-by-Marguerite-Beaudry.pdf
    • http://solosopos.myhome.cx/1851852856855854850/The-Rise-Of-The-French-Novel-Marivaux-Crb-illon-I-E-Crb-il