Malicious PDF — malware analysis report

Static analysis result for SHA-256 fee739f4868fcf94…

MALICIOUS

PDF

16.1 KB Created: 2020-03-18 23:00:51 +00:00 Authoring application: mPDF 5.7
MD5: 6f34c81ad03b1fdb67a3ee6e3e31909c SHA-1: 41ea6815c7324a28cecf20aea05dbee35e122e25 SHA-256: fee739f4868fcf94e2c62c25b501423ca142b6746ab1eda72a3ca5f3925630e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to redirect users to malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the dominant host being 'weisncio.myhome.cx'. This suggests the document's primary purpose is to drive traffic to these external links, likely as a form of phishing or malware distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620620621627/Avatar-The-Last-Airbender-The-Rift-Part-1-The-Rift-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2624629625628621/Avatar-The-Last-Airbender-The-Promise-Avatar-The-Last-Airbender-Library-Edition-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628627629629/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/5621624626627/Avatar-The-Last-Airbender-The-Search-Part-3-The-Search-3-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1620623628628/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628625620621/Avatar-The-Last-Airbender-North-and-South-Part-2-North-and-South-2-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628623624627/Avatar-The-Last-Airbender-Smoke-and-Shadow-Part-3-Smoke-and-Shadow-3-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/2628628623624620/Avatar-The-Last-Airbender-North-and-South-Part-1-North-and-South-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1620628624624/The-Eternal-Smile-Three-Stories-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1624629621622/American-Born-Chinese-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/3627623621624620/Free-Comic-Book-Day-2015-All-Ages-6-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/1624628620628/Boxers-Boxers-amp-Saints-1-by-Gene-Luen-Yang.pdf
    • http://weisncio.myhome.cx/7622622621623/Avatar-Volume-4-The-Last-Airbender-Avatar-4-by-Michael-Dante-DiMartino.pdf
    • http://weisncio.myhome.cx/4626622626626/Avatar-Volume-1-The-Last-Airbender-Avatar-1-by-Michael-Dante-DiMartino.pdf
    • http://weisncio.myhome.cx/8624622628624626/Across-the-Rift-by-H-Ann-Ackroyd.pdf
    • http://weisncio.myhome.cx/2629629626627625/Mending-the-Rift-by-Chris-T-Kat.pdf
    • http://weisncio.myhome.cx/2629629624624/Running-the-Rift-by-Naomi-Benaron.pdf
    • http://weisncio.myhome.cx/1621623623629627627/Destiny-s-Rift-Broken-Well-2-by-Sam-Bowring.pdf
    • http://weisncio.myhome.cx/4623628628622625/The-Starry-Rift-by-James-Tiptree-Jr-.pdf
    • http://weisncio.myhome.cx/4626621621620622/Avatar-The-Last-Airbender-Legacy-by-Michael-Teitelbaum.pdf
    • http://weisncio.myhome.cx/2628628623624620/Avatar-The-Last-Airbender-North-and-South-Part-1-North-and