Malicious PDF — malware analysis report

Static analysis result for SHA-256 db5594084c2e6fbb…

MALICIOUS

PDF

16.8 KB Created: 2020-03-12 02:16:50 +00:00 Authoring application: mPDF 5.7
MD5: 683d1a3c62b5796ca40896699031fc1b SHA-1: f1be82b954819b31573d24139e3f180a64820f3a SHA-256: db5594084c2e6fbb851e179485e78be6d8a823e2ea37311aa998a9ca0818f341
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external PDF files hosted on the same domain, suggesting a link farm or a distribution mechanism for further malicious content. No scripts were extracted from this sample. The primary attack pattern involves leveraging these embedded links for malicious purposes.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620623628628/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628627629629/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2624629625628621/Avatar-The-Last-Airbender-The-Promise-Avatar-The-Last-Airbender-Library-Edition-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1620620621627/Avatar-The-Last-Airbender-The-Rift-Part-1-The-Rift-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/5621624626627/Avatar-The-Last-Airbender-The-Search-Part-3-The-Search-3-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628623624627/Avatar-The-Last-Airbender-Smoke-and-Shadow-Part-3-Smoke-and-Shadow-3-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628623624620/Avatar-The-Last-Airbender-North-and-South-Part-1-North-and-South-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628625620621/Avatar-The-Last-Airbender-North-and-South-Part-2-North-and-South-2-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1620628624624/The-Eternal-Smile-Three-Stories-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1624629621622/American-Born-Chinese-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/3627623621624620/Free-Comic-Book-Day-2015-All-Ages-6-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1624628620628/Boxers-Boxers-amp-Saints-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/4626622626626/Avatar-Volume-1-The-Last-Airbender-Avatar-1-by-Michael-Dante-DiMartino.pdf
    • http://weisncio.myhome.cx/7622622621623/Avatar-Volume-4-The-Last-Airbender-Avatar-4-by-Michael-Dante-DiMartino.pdf
    • http://weisncio.myhome.cx/1628629628629621/Promise-Road-Walking-Through-the-Process-that-Manifests-the-Promise-by-Letetia-Mullenix.pdf
    • http://weisncio.myhome.cx/9628629624622/Promise-of-Home-Promise-Series---the-Grahams-Book-2-by-Jennifer-Woodhull.pdf
    • http://weisncio.myhome.cx/1622624628/Broken-Promise-Promise-Falls-1-by-Linwood-Barclay.pdf
    • http://weisncio.myhome.cx/1628628622626624/Promise-Me-Always-Pinky-Promise-Sisterhood-1-by-Christine-Lynxwiler.pdf
    • http://weisncio.myhome.cx/1621625622621624623/God-s-Story---Through-The-Bible-Promise-By-Promise-by-Philip-Greenslade.pdf
    • http://weisncio.myhome.cx/3628623624622/Promise-Me-Light-Promise-Me-2-by-Paige-Weaver.pdf
    • http://weisncio.myhome.cx/2628628623624620/Avatar-The-Last-Airbender-North-