Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ce0cfb00e321653…

MALICIOUS

PDF

21.0 KB Created: 2020-03-15 00:49:09 +00:00 Authoring application: mPDF 5.7
MD5: 55e0369023381e432e06eed05d0e83ab SHA-1: 3c312d64ea1a9c6ffddf0899c08092a88a985848 SHA-256: 1ce0cfb00e321653a6a3c63b0336f03a2d2dbd8d89db39c31a7c7c6666b54f20
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files on the domain lwoscmobook.myhome.cx. This heuristic firing suggests a link farm or a method to distribute further malicious content. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the exact intent beyond the URL distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252425245524052425247/Holding-Holly-Love-and-Football-4-5-by-Julie-Brannagh.pdf
    • http://lwoscmobook.myhome.cx/252485242524352415249/Rushing-Amy-Love-and-Football-2-by-Julie-Brannagh.pdf
    • http://lwoscmobook.myhome.cx/252485242524352415243/Blitzing-Emily-Love-and-Football-1-by-Julie-Brannagh.pdf
    • http://lwoscmobook.myhome.cx/152435248524152495247/Stress-Less-Weigh-Less-Follow-Holly-to-Increase-Energy-Eat-the-Food-You-Love-and-Enjoy-an-Ageless-Body-by-Holly-Mosier.pdf
    • http://lwoscmobook.myhome.cx/152445246524652465241/Holding-You-Love-Wanted-In-Texas-3-by-Kelly-Elliott.pdf
    • http://lwoscmobook.myhome.cx/352455248524352445247/Why-Men-Love-Bitches-From-Doormat-to-Dreamgirl-A-Woman-s-Guide-to-Holding-Her-Own-in-a-Relationship-by-Sherry-Argov.pdf
    • http://lwoscmobook.myhome.cx/75242524352405249/Game-For-Love-Bad-Boys-of-Football-3-by-Bella-Andre.pdf
    • http://lwoscmobook.myhome.cx/852445249524752435241/Belgian-Football-Clubs-Standard-Liege-K-A-A-Gent-Kv-Mechelen-K-R-C-Genk-Football-in-Belgium-S-Du-Pays-de-Charleroi-Lierse-S-K-by-Source-Wikipedia.pdf
    • http://lwoscmobook.myhome.cx/252485248524352445249/Football-Players-Love-Milk-Hucow-University-2-by-Jezebel-Divelle.pdf
    • http://lwoscmobook.myhome.cx/952445243524152435247/Football-Outsiders-Almanac-2010-The-Essential-Guide-to-the-2010-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdf
    • http://lwoscmobook.myhome.cx/852415247524652425245/A-Friday-Night-Lights-Companion-Love-Loss-and-Football-in-Dillon-Texas-by-Leah-Wilson.pdf
    • http://lwoscmobook.myhome.cx/952445243524052475246/Pro-Football-Prospectus-2007-The-Essential-Guide-to-the-2007-Pro-Football-Season-by-Aaron-Schatz.pdf
    • http://lwoscmobook.myhome.cx/252455245524852435242/Holding-You-Holding-You-1-by-Jewel-E-Ann.pdf
    • http://lwoscmobook.myhome.cx/85241524352425240/Holding-You-Holding-You-1-by-Jewel-E-Ann.pdf
    • http://lwoscmobook.myhome.cx/252445243524752455243/Love-Hurts-The-Killing-of-Rose-Love-Hurts-1-by-Holly-Hood.pdf
    • http://lwoscmobook.myhome.cx/55240524952435242/Love-vs-Lust-Eternal-War-2-by-Holly-Vane.pdf
    • http://lwoscmobook.myhome.cx/152495247524652465248/Love-and-Other-Natural-Disasters-by-Holly-Shumas.pdf
    • http://lwoscmobook.myhome.cx/85244524252415242/The-Billionaire-s-First-Christmas-Winters-Love-1-by-Holly-Rayner.pdf
    • http://lwoscmobook.myhome.cx/152405240524252455245/The-Right-Number-Love-Conquers-All-Series-Book-1-by-Holly-Haven.pdf
    • http://lwoscmobook.myhome.cx/252455248524652405248/Love-Me-Softly-by-Julie-Jameson.pdf