Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcb15eb03c848ee1…

MALICIOUS

PDF

20.7 KB Created: 2020-03-14 00:55:22 +00:00 Authoring application: mPDF 5.7
MD5: 5f94b76f5d2950db79f24d9d4b36fdb8 SHA-1: 0cb6e1153292b6fc0b18dfb477e4f0c407865211 SHA-256: fcb15eb03c848ee1407e7948e27523873bd33e0d77b87e31bccf990bdab0d3ba
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect the user to potentially harmful content hosted on 'weisncio.myhome.cx'.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/3628627627627626/Is-That-What-People-Do-Short-Stories-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/4625625624625622/Store-of-the-Worlds-The-Stories-of-Robert-Sheckley-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/4625626629623626/The-People-Trap-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/4626625622625629/The-People-Trap-Plus-Mindswap-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/9627626629627/Contemplations-amp-Short-Stories-of-a-Tzaddik-The-Thoughts-Dreams-amp-Stories-of-Holy-People-by-Charlayne-Crawford.pdf
    • http://weisncio.myhome.cx/2622625627623623/Mindswap-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/4625626629623624/Store-of-Infinity-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/5620624623625620/The-Cruel-Equations-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/4623625621625622/Human-Man-s-Burden-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/6620620629627/The-Status-Civilization-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/1626621620623624/Untouched-By-Human-Hands-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/3628626625626628/The-Gay-Icon-Contemporary-Short-Stories-by-Robert-Joseph-Greene.pdf
    • http://weisncio.myhome.cx/3621623626624620/Short-Elementary-Level-Stories-Bundle-2-3-Short-Stories-in-1-Ebook-Books-about-Santa-mystery-space-animals-planets-family-Perfect-for-kids-under-10-learning-to-read-by-Betty-J-Byers.pdf
    • http://weisncio.myhome.cx/4624624625629620/Short-Story-Masterpieces-35-Classic-American-and-British-Stories-from-the-First-Half-of-the-20th-Century-by-Robert-Penn-Warren.pdf
    • http://weisncio.myhome.cx/3623624624629620/Balkan-Beauty-Balkan-Blood-Modern-Albanian-Short-Stories-by-Robert-Elsie.pdf
    • http://weisncio.myhome.cx/7625625623628621/JAMES-LEE-BURKE-BOOKS-AND-ALL-SHORT-STORIES-CHECKLIST-AND-SUMMARIES---INCLUDES-LATEST-DAVE-ROBICHEAUX---JAMES-LEE-BURKE-SHORT-STORIES-AND-STANDALONE-NOVELS-AND-CHECKLIST-BEST-READING-ORDER-Book-56-by-Avid-Reader.pdf
    • http://weisncio.myhome.cx/4624625625622621/An-Anthology-of-Chinese-Short-Short-Stories-Panda-Books-by-Harry-J-Huang.pdf
    • http://weisncio.myhome.cx/1626624620621629/100-Great-Science-Fiction-Short-Short-Stories-by-Isaac-Asimov.pdf
    • http://weisncio.myhome.cx/7621620622623621/The-Summer-Vacation-A-Short-Horror-Story-Short-Stories-Book-1-by-Taiden-Dashner-Gabaldon.pdf
    • http://weisncio.myhome.cx/9626621622623620/Draconian-New-York-Hob-Draconian-2-by-Robert-Sheckley.pdf
    • http://weisncio.myhome.cx/1626621620623624/Untouched-By-Human-Hands-by-Robert-Sheckle