Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcab9511d0ebc4fb…

MALICIOUS

PDF

23.3 KB Created: 2020-03-18 22:43:12 +00:00 Authoring application: mPDF 5.7
MD5: 85d6e862391c8645116f3240cfc94400 SHA-1: 4737e914544283be3ca518c98ae5cdfd75cc7948 SHA-256: dcab9511d0ebc4fbf4f9e093ed0c4e7a77ba19cb315985c9d727ee154cd13871
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a single domain, indicating a link farm designed to redirect users to potentially malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. No scripts were extracted from this sample. The primary attack pattern involves luring users to external resources via a large number of links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/7868865862861863/Blair-s-Chronological-and-Historical-Tables-from-the-Creation-to-the-Present-Time-With-Additions-and-Corrections-from-the-Most-Authentic-Writers-Including-the-Computation-of-St-Paul-as-Connecting-the-Period-from-the-Exode-to-the-Temple-by-John-Blair.pdf
    • http://calistazz.myhome.cx/1861862866861864869/A-Statement-of-the-Satisfactory-Results-Which-Have-Attended-Emigration-to-Upper-Canada-from-the-Establishment-of-the-Canada-Company-Until-the-Present-Period-Comprising-Statistical-Tables-and-Other-Important-Information-Communicated-by-by-Frederick-Widder.pdf
    • http://calistazz.myhome.cx/5861862869869863/American-Standard-by-John-Blair.pdf
    • http://calistazz.myhome.cx/1867869863865861/Positive-Pollutions-and-Cultural-Toxins-Waste-and-Contamination-in-Contemporary-U-S-Ethnic-Literatures-by-John-Blair-Gamber.pdf
    • http://calistazz.myhome.cx/7861869864868867/You-Can-Present-with-Confidence-How-to-Speak-Like-a-Pro-Dazzle-Your-Audience-and-Get-the-Results-You-Want-Every-Time-by-Paul-Du-Toit.pdf
    • http://calistazz.myhome.cx/3863864862866866/Stay-With-Me-by-Jessica-Blair.pdf
    • http://calistazz.myhome.cx/3862867865866869/Secret-Lucidity-by-E-K-Blair.pdf
    • http://calistazz.myhome.cx/4861865864865868/Author-Anonymous-by-E-K-Blair.pdf
    • http://calistazz.myhome.cx/4860865864866868/The-Billionaire-Bum-by-Samantha-Blair.pdf
    • http://calistazz.myhome.cx/1861864867868862861/Because-of-the-Camels-by-Brenda-Blair.pdf
    • http://calistazz.myhome.cx/7862864865862860/Lost-in-the-Affair-by-E-K-Blair.pdf
    • http://calistazz.myhome.cx/5860868862869863/Shadow-Path-by-P-L-Blair.pdf
    • http://calistazz.myhome.cx/1862861867863862/Stroika-by-Mark-Blair.pdf
    • http://calistazz.myhome.cx/5862861860868862/Last-Heat-by-Peter-Blair.pdf
    • http://calistazz.myhome.cx/3865865868864862/The-Quarterback-by-Mackenzie-Blair.pdf
    • http://calistazz.myhome.cx/1865860863862/Places-Left-Unfinished-at-the-Time-of-Creation-by-John-Phillip-Santos.pdf
    • http://calistazz.myhome.cx/5865864861862867/Vendedores-Perros-by-Blair-Singer.pdf
    • http://calistazz.myhome.cx/2863862869866860/The-Beckoning-Shadow-by-Katharyn-Blair.pdf
    • http://calistazz.myhome.cx/4864869866862860/The-River-Nile-by-Kenny-Blair.pdf
    • http://calistazz.myhome.cx/4869867860867861/A-Highlander-s-Destiny-by-Willa-Blair.pdf