Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecdd99fb59d7a834…

MALICIOUS

PDF

18.4 KB Created: 2020-03-15 10:33:00 +00:00 Authoring application: mPDF 5.7
MD5: 54f9c19f718558d0448a53dcd1e0a565 SHA-1: 3b10da8bbe80f6b291f4907dbdc79e38e9ea1b89 SHA-256: ecdd99fb59d7a8341d9a7b801379465a84d6851f15be7b7137b5c79871ad5b5e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, indicating a potential link farm or a distribution mechanism for further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this is the primary function of the document. While no scripts were extracted, the sheer volume of links to external PDFs hosted on 'kitasdyu.myhome.cx' points to a content-delivery or redirection strategy. The document body was heavily obfuscated and unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1878877872875878/The-Winter-Calf-Maple-Gap-1-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/1870878874877870/The-Winter-Calf-Maple-Gap-1-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/2878879872871877/The-Last-Buffalo-Soldier-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/2878876873875877/Frozen-Highway-by-Michael-S-Nuckols.pdf
    • http://kitasdyu.myhome.cx/1871874871874871/M-Is-for-Maple-A-Canadian-Alphabet-by-Michael-Ulmer.pdf
    • http://kitasdyu.myhome.cx/9879877872879/Architects-Are-Here-by-Michael-Winter.pdf
    • http://kitasdyu.myhome.cx/1874871879873872/This-All-Happened-by-Michael-Winter.pdf
    • http://kitasdyu.myhome.cx/2871873878870870/Winter-s-Heart-by-Michael-Kanuckel.pdf
    • http://kitasdyu.myhome.cx/2877878877873870/The-Hammer-of-the-Sun-The-Winter-of-the-World-3-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/5874873875877/The-Anvil-of-Ice-The-Winter-of-the-World-1-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/3873878875875876/The-Disappearance-of-Winter-s-Daughter-The-Riyria-Chronicles-4-by-Michael-J-Sullivan.pdf
    • http://kitasdyu.myhome.cx/4877879871875872/The-Castle-of-the-Winds-The-Winter-of-the-World-4-by-Michael-Scott-Rohan.pdf
    • http://kitasdyu.myhome.cx/9871875876877871/Collected-Plays-Two-Man-equals-Man-The-Elephant-Calf-The-Threepenny-Opera-The-Rise-and-Fall-of-the-City-of-Mahagonny-and-The-Seven-Deadly-Sins-by-Bertolt-Brecht.pdf
    • http://kitasdyu.myhome.cx/7876872875878873/Champ-and-Me-By-the-Maple-Tree-by-Ed-Shankman.pdf
    • http://kitasdyu.myhome.cx/7874871879878878/Solving-Odes-with-Maple-V-by-David-Barrow.pdf
    • http://kitasdyu.myhome.cx/8870878876873875/Secrets-at-Maple-Syrup-Farm-by-Rebecca-Raisin.pdf
    • http://kitasdyu.myhome.cx/7878878871872871/Jewish-Wife-and-Other-Short-Plays-Includes-In-Search-of-Justice-Informer-Elephant-Calf-Measures-Taken-Exception-and-the-Rule-Salzburg-Dance-of-Death-by-Bertolt-Brecht.pdf
    • http://kitasdyu.myhome.cx/2879879878876875/The-Orphan-and-the-Omega-Maple-Ridge-Wolves-1-by-Harper-B-Cole.pdf
    • http://kitasdyu.myhome.cx/7875877871874877/Defining-Moments-The-Toronto-Maple-Leafs-by-Mike-Leonetti.pdf
    • http://kitasdyu.myhome.cx/3870876870879874/Sugaring-A-Maple-Syrup-Memoir-with-Instructions-by-Susan-Carol-Hauser.pdf
    • http://kitasdyu.myhome.cx/5874873875877/T