Malicious PDF — malware analysis report

Static analysis result for SHA-256 5004f7ca3247498c…

MALICIOUS

PDF

20.0 KB Created: 2020-03-18 21:08:26 +00:00 Authoring application: mPDF 5.7
MD5: 5a2b65e676cd9532935c71a06d653585 SHA-1: 8ed1abd66739f0bb0ef53d1d79b5874f0e0e1f95 SHA-256: 5004f7ca3247498c73c6dad2c34806f1702c6f294f2f4de477bcacdcaff44a0f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with 32 external links embedded within the document. The dominant host for these links is kitasdyu.myhome.cx. This suggests the document is designed to lure users to a collection of potentially malicious websites, possibly for phishing or malware distribution. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/2873872878872871/The-Market-by-Allie-Wilder.pdf
    • http://kitasdyu.myhome.cx/2873872878872878/House-Guests-by-Allie-Wilder.pdf
    • http://kitasdyu.myhome.cx/2873872878873870/The-girl-in-the-coffee-shop-by-Allie-Wilder.pdf
    • http://kitasdyu.myhome.cx/8879879873873879/I-Love-You-with-Custard-on-Top-And-Other-Notes-from-the-Wilder-Shores-of-Love-by-Oonagh-O-39-Hagan.pdf
    • http://kitasdyu.myhome.cx/1873878870871873/Allies-amp-Assassins-Allies-amp-Assassins-1-by-Justin-Somper.pdf
    • http://kitasdyu.myhome.cx/2870873873871875/The-Wilder-Shores-of-Love-by-Madeleine-Ker.pdf
    • http://kitasdyu.myhome.cx/1870872875879877871/Tips-for-Running-18-Interesting-Tips-for-Runners-by-Alan-Seel.pdf
    • http://kitasdyu.myhome.cx/8870872873874/Laura-Ingalls-Wilder-and-Rose-Wilder-Lane-Authorship-Place-Time-and-Culture-by-John-E-Miller.pdf
    • http://kitasdyu.myhome.cx/8871873875877874/How-to-be-Happy-and-Love-your-Life-Charming-Tips-East-to-read-Inspiring-amp-Simple-by-April-Salee.pdf
    • http://kitasdyu.myhome.cx/9875871872874/Fabulosity-Is-You-A-Woman-s-Guide-For-Building-Her-Confidence-Fashion-Tips-Weight-Loss-Tips-Skin-Care-Secrets-Relationships-and-Pursuing-Her-Purpose-by-Winsome-Campbell-Green.pdf
    • http://kitasdyu.myhome.cx/1873878871877879/West-from-Home-Letters-of-Laura-Ingalls-Wilder-San-Francisco-1915-Little-House-11-by-Laura-Ingalls-Wilder.pdf
    • http://kitasdyu.myhome.cx/3879871877874873/Laura-Ingalls-Wilder-Farm-Journalist-Writings-from-the-Ozarks-by-Laura-Ingalls-Wilder.pdf
    • http://kitasdyu.myhome.cx/1871879873877873872/Invisible-Allies-by-Aleksandr-Solzhenitsyn.pdf
    • http://kitasdyu.myhome.cx/1871871873876875/Enemies-amp-Allies-by-Kevin-J-Anderson.pdf
    • http://kitasdyu.myhome.cx/2875871876875871/Dangerous-Allies-WWII-1-by-Renee-Ryan.pdf
    • http://kitasdyu.myhome.cx/9870870872874876/The-Boy-Allies-with-Haig-in-Flanders-by-Clair-W-Hayes.pdf
    • http://kitasdyu.myhome.cx/2873875870877870/The-Allies-American-Family-Portrait-6-by-Jack-Cavanaugh.pdf
    • http://kitasdyu.myhome.cx/9875875873878871/The-Unlikely-Allies-1939-House-of-Winslow-36-by-Gilbert-Morris.pdf
    • http://kitasdyu.myhome.cx/7877875870873877/Adversaries-into-Allies-Win-People-Over-Without-Manipulation-or-Coercion-by-Bob-Burg.pdf
    • http://kitasdyu.myhome.cx/1879873875874872/Spider-Girl-Volume-3-Avenging-Allies-by-Tom-DeFalco.pdf
    • http://kitasdyu.myhome.cx/8870872873874/Laura-Ingalls-Wilder-and-Rose-W