Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e0a844b8a66dc09…

MALICIOUS

PDF

18.1 KB Created: 2020-02-06 00:42:04 +00:00 Authoring application: mPDF 5.7
MD5: 626247e51e249e46122cc829fd459d98 SHA-1: 1f2b44ef8fb76fec5d38400f1468cf1503b04e2e SHA-256: 1e0a844b8a66dc09bc2ad2e30bb9100afdb772b4ed28527ec70a99ffe85e8b5f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the domain lwoscmobook.myhome.cx. The intent appears to be to direct the user to click these links, potentially leading to a malicious website or further compromise. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252485240524552495244/Long-Night-Moon-Seasons-of-the-Moon-3-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/152435245524352485245/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/152435245524452435243/Moon-of-the-Terrible-Seasons-of-the-Moon-Cain-Chronicles-3-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/252485240524252475244/All-Hallows-Moon-Seasons-of-the-Moon-2-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/252485240524552495249/Of-Wings-and-Wolves-Seasons-of-the-Moon-Cain-Chronicles-6-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/25241524152465242/Long-Night-Moon-by-Theresa-Weir.pdf
    • http://lwoscmobook.myhome.cx/352475248524852435240/The-Shifting-Moon-Werewolves-and-Wallflowers-2-by-Harper-Long.pdf
    • http://lwoscmobook.myhome.cx/352425248524152425240/Mrs-Darley-s-Moon-Mysteries-A-Celebration-Of-Moon-Lore-And-Magic-by-Carole-Carlton.pdf
    • http://lwoscmobook.myhome.cx/752485245524952475248/Moon-Shot-The-Inside-Story-of-America-s-Race-to-the-Moon-by-Alan-Shepard.pdf
    • http://lwoscmobook.myhome.cx/952465242524152425249/Moon-O-Theism-Religion-of-a-War-and-Moon-God-Prophet-Volume-I-of-II-by-Yoel-Natan.pdf
    • http://lwoscmobook.myhome.cx/652445244524152485242/The-Adventures-of-Tintin-Vol-5-Land-of-Black-Gold-Destination-Moon-Explorers-on-the-Moon-by-Herg-.pdf
    • http://lwoscmobook.myhome.cx/2524852435248/The-Moon-in-the-Palace-Empress-of-Bright-Moon-1-by-Weina-Dai-Randel.pdf
    • http://lwoscmobook.myhome.cx/352495242524152435245/Moon-Bayou-Samantha-Moon-Case-Files-1-by-J-R-Rain.pdf
    • http://lwoscmobook.myhome.cx/852475242524652455242/Full-Moon-Feral-Moon-Compound-2-by-Jackie-Nacht.pdf
    • http://lwoscmobook.myhome.cx/55249524952455249/Haunted-Moon-Otherworld-Sisters-of-the-Moon-13-by-Yasmine-Galenorn.pdf
    • http://lwoscmobook.myhome.cx/352475244524852495246/Thanking-the-Moon-Celebrating-the-Mid-Autumn-Moon-Festival-by-Grace-Lin.pdf
    • http://lwoscmobook.myhome.cx/452455241524152475247/Harvest-Moon-Blue-Moon-Lake-2-by-Sharon-Struth.pdf
    • http://lwoscmobook.myhome.cx/252485240524652495247/Black-Moon-Silver-Moon-2-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/1524052495243524952495241/Silver-Moon-Moon-Trilogy-Part-III-by-C-L-Bevill.pdf
    • http://lwoscmobook.myhome.cx/452425241524852405242/Scarlet-Moon-Children-of-the-Blood-Moon-1-by-S-D-Grimm.pdf
    • http://lwoscmobook.myhome.cx/952465242524152425249/Mo