Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c7f40077185602a…

MALICIOUS

PDF

20.9 KB Created: 2020-03-18 11:22:14 +00:00 Authoring application: mPDF 5.7
MD5: 5db142cb77762d90b7c5a15e0a28d72f SHA-1: e4f6c8d9c496c9216775ef0ce1e40f73cca7108a SHA-256: 3c7f40077185602a74b5b841e9937561545dce54ca5a123adfbbe9f7227dfdc2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified as a PDF SEO link farm. The primary purpose appears to be directing users to external content hosted on easckaolp.myhome.cx. While no scripts were extracted, the sheer volume of links suggests a malicious intent, potentially for SEO spam or to distribute further malware. The attack pattern is consistent with a document used for link farming or as a lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/1841842848848844844/Mein-Nachbar-der-Million-r-by-Verena-Bergmeier.pdf
    • http://easckaolp.myhome.cx/1841844842845847848/Mein-gel-schtes-Leben-Wie-ich-mein-Ged-chtnis-verlor-und-mich-selber-fand-by-Scott-Bolzan.pdf
    • http://easckaolp.myhome.cx/1840849845848846844/Lebenserinnerungen-Vol-1-Mein-Wirken-ALS-Rechtslehrer-Mein-Anteil-an-Der-Politik-in-Kirche-Und-Staat-by-Johann-Friedrich-Schulte.pdf
    • http://easckaolp.myhome.cx/9844846843844849/Warum-die-Reichen-reicher-werden-und-Ihr-Nachbar-so-aussieht-wie-Sie-Neue-Erkenntnisse-aus-der-Sozialphysik-by-Mark-Buchanan.pdf
    • http://easckaolp.myhome.cx/8846849846842842/The-Art-of-Annemieke-Mein-Wildlife-Artist-in-Textiles-by-Annemieke-Mein.pdf
    • http://easckaolp.myhome.cx/1840841842846845843/Saying-Goodbye-to-Verena-by-Ivy-Turow.pdf
    • http://easckaolp.myhome.cx/1840841842846845847/Balik-Kampung-by-Verena-Tay.pdf
    • http://easckaolp.myhome.cx/1840841842848844841/Balik-Kampung-2B-Contemplations-by-Verena-Tay.pdf
    • http://easckaolp.myhome.cx/1840842848849849845/Linus-P-und-ein-Aufsatz-mit-Folgen-by-Verena-K-Bauer.pdf
    • http://easckaolp.myhome.cx/9842842849848846/Geile-Fickspiele-mit-der-G-rtnerin-by-Verena-Mannsfeld.pdf
    • http://easckaolp.myhome.cx/1841849845848848846/Das-Gl-ck-in-wei-en-N-chten-by-Verena-Rabe.pdf
    • http://easckaolp.myhome.cx/1840840840845844842/Susi-will-ein-Krampus-sein-by-Verena-J-rgo.pdf
    • http://easckaolp.myhome.cx/1841844844842841841/Janine---Gefickt-von-drei-M-nnern-by-Verena-Mannsfeld.pdf
    • http://easckaolp.myhome.cx/1841845847846843843/Kundenbindung-im-Multi-Channel-Management-von-Banken-by-Verena-Schabbach.pdf
    • http://easckaolp.myhome.cx/1840840844847849846/Auf-jeden-Fall-nichts-mit-Menschen-Geschichten-aus-dem-Leben-by-Verena-Dittrich.pdf
    • http://easckaolp.myhome.cx/1841841849843844844/Der-Romische-Limes-in-Osterreich-Fuhrer-Zu-Den-Archaologischen-Denkmalern-by-Verena-Gassner.pdf
    • http://easckaolp.myhome.cx/1840840849849849847/Zwischen-Gegenwart-Und-Zukunft-Dystopien-in-Romanen-Des-21-Jahrhunderts-by-Verena-Rumpf.pdf
    • http://easckaolp.myhome.cx/1841840849849841849/Die-Wunden-Des-Staates-Kriegsopfer-Und-Sozialstaat-in-Osterreich-1914-1938-by-Verena-Pawlowsky.pdf
    • http://easckaolp.myhome.cx/1840841842849849846/Europaische-Salons-Hohepunkte-Einer-Versunkenen-Weiblichen-Kultur-by-Verena-von-der-Heyden-Rynsch.pdf
    • http://easckaolp.myhome.cx/1840848841845845841/Room-27-Zur-falschen-Zeit-am-falschen-Ort-by-Verena-Kiefer.pdf