Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcd380ca903a4113…

MALICIOUS

PDF

14.3 KB Created: 2020-03-19 03:48:01 +00:00 Authoring application: mPDF 5.7
MD5: 62f1209ca72b10b700a9a51d8b710021 SHA-1: 185a2ea99726d2775d961e15b61cf87ddea28aec SHA-256: fcd380ca903a4113c288407981b503489763773877166d8892769f0c359c86f8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was identified as malicious due to a critical heuristic firing for a link farm. It contains numerous embedded URLs, all pointing to external PDF files hosted on the same domain. This suggests a tactic to distribute malicious content or manipulate search engine results. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/3879879873875877/The-Horsemaster-s-Daughter-Calhoun-Chronicles-2-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/3870872876878877/The-Charm-School-Calhoun-Chronicles-1-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1871877878874/Fireside-Lakeshore-Chronicles-5-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/2878875878876878/Fireside-Lakeshore-Chronicles-5-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1878872874875874/The-Winter-Lodge-Lakeshore-Chronicles-2-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1875877870/Starlight-on-Willow-Lake-Lakeshore-Chronicles-11-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/3874874872879872/Summer-at-Willow-Lake-The-Lakeshore-Chronicles-1-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1871878871875/Lakeshore-Christmas-Lakeshore-Chronicles-6-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1872871878877/The-Ocean-Between-Us-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1872872871870/Summer-by-the-Sea-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1872871870874/Table-for-Five-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/2871877871872874/The-You-I-Never-Knew-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/2871871872874878/The-Lightkeeper-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/3872870878879873/The-Apple-Orchard-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/2871870876877873/Home-Before-Dark-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/3875877877874872/Lakeside-Cottage-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/4879873870873870/The-Lily-and-the-Leopard-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/9870875878876871/Der-Geschmack-von-wildem-Honig-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/1872878872877/At-the-King-s-Command-Tudor-Rose-1-by-Susan-Wiggs.pdf
    • http://kitasdyu.myhome.cx/4876876877874876/The-Horsemaster-s-Notebook-by-Mary-Rose.pdf
    • http://kitasdyu.myhome.cx/2871