Malicious PDF — malware analysis report

Static analysis result for SHA-256 542c2f330905060f…

MALICIOUS

PDF

24.2 KB Created: 2020-03-21 08:57:51 +00:00 Authoring application: mPDF 5.7
MD5: 8b6bfe29c1389788ac157dee96aac8a4 SHA-1: 5ab7b596c6bc1ba111c0f117a08baf44954df41e SHA-256: 542c2f330905060f82af15353a4ae513a63e2a4355612a804acaebc2414e038c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files hosted on a suspicious domain, indicative of a link farm or redirection scheme. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. No scripts were extracted from this sample. The primary attack pattern involves luring the user to click on these links, potentially leading to further malicious content or exploitation.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/6551556553550553/Life-and-Times-of-Frederick-Douglass-Written-by-Himself-His-Early-Life-as-a-Slave-His-Escape-from-Bondage-and-His-Complete-History-to-the-Present-Time-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/6551556550559557/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-Written-by-Himself-Critical-Edition-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/4550551552555559/Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-and-Essays-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/3551555553556551/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/2556553559552552/The-Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/5559550555559557/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/1551552550557558554/Narrative-of-the-Life-of-Frederick-Douglass-Annotated-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/3553555559556/Narrative-of-the-Life-of-Frederick-Douglass-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/4552556554554559/Narrative-of-the-Life-of-Frederick-Douglass-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/8550557559553552/Narrative-of-the-Life-of-Frederick-Douglass-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/6559559550557556/Facing-Frederick-The-Life-of-Frederick-Douglass-a-Monumental-American-Man-by-Tonya-Bolden.pdf
    • http://ieuicufioao.myhome.cx/8555551558555551/Narratives-Of-The-Life-Of-Frederick-Douglas-And-Walden-Color-Illustrated-Formatted-for-E-Readers-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/4553556553555551/The-Life-of-Frederick-Douglas-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/4559551558551550/Three-African-American-Classics-Up-from-Slavery-The-Souls-of-Black-Folk-Narrative-of-the-Life-of-Frederick-Douglass-by-Booker-T-Washington.pdf
    • http://ieuicufioao.myhome.cx/3553550557551551/My-Bondage-and-My-Freedom-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/2554555551559555/Frederick-Douglass-Fights-For-Freedom-by-Margaret-Davidson.pdf
    • http://ieuicufioao.myhome.cx/2557559555555559/Frederick-Douglass-Prophet-of-Freedom-by-David-W-Blight.pdf
    • http://ieuicufioao.myhome.cx/1554556556556/Frederick-Douglass-Slave---Fighter---Freeman-by-Arna-Bontemps.pdf
    • http://ieuicufioao.myhome.cx/8552559558552556/Once-Upon-a-Slave-28-Powerful-Memoirs-of-Former-Slaves-amp-100-Recorded-Testimonies-in-One-Edition-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/8552559557558553/100-Reward-on-my-Head-Powerful-amp-Unflinching-Memoirs-of-Former-Slaves-28-Narratives-in-One-Volume-by-Frederick-Douglass.pdf
    • http://ieuicufioao.myhome.cx/2556553559552552/The-Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-by-Frederick-Doug