Malicious PDF — malware analysis report

Static analysis result for SHA-256 8951ab02e7ef0b26…

MALICIOUS

PDF

19.3 KB Created: 2020-03-16 04:14:45 +00:00 Authoring application: mPDF 5.7
MD5: 94d34a0a79892d38da35a4c09faf616a SHA-1: cd13061ef6113024a6f620faa4ecd031807c978b SHA-256: 8951ab02e7ef0b266af20761e2ed285d3c091fe237142f54516eadd314dd81f6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to drive traffic to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior. No scripts were extracted from this sample. The primary IOCs are the domain and the numerous linked URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1558553559555552/Finding-Love-In-The-Sweet-Life-A-Missing-Ingredient-Romance-Novel-by-Diann-Dean.pdf
    • http://ieuicufioao.myhome.cx/4554559551553558/The-Missing-Ingredient-by-Brian-Lancaster.pdf
    • http://ieuicufioao.myhome.cx/4552554556554552/Dizzy-amp-Jimmy-My-Life-with-James-Dean-A-Love-Story-by-Liz-Sheridan.pdf
    • http://ieuicufioao.myhome.cx/4554550554556556/The-Paramedic-s-Second-Chance-Sweet-Contemporary-Beach-Romance-Hawthorne-Harbor-Second-Chance-Romance-Book-1-by-Elana-Johnson.pdf
    • http://ieuicufioao.myhome.cx/1557550552552550/Love-Me-Back-to-Life-Gold-Coast-Romance-1-by-Elle-G-Mraz.pdf
    • http://ieuicufioao.myhome.cx/1551558555559559/The-Sweet-Relief-of-Missing-Children-by-Sarah-Braunstein.pdf
    • http://ieuicufioao.myhome.cx/2552550559556/Gone-Missing-A-Jonelle-Sweet-Mystery-Book-2-by-R-Lanier-Clemons.pdf
    • http://ieuicufioao.myhome.cx/9550557554558552/Finding-Our-Tongues-Mothers-Infants-and-the-Origins-of-Language-by-Dean-Falk.pdf
    • http://ieuicufioao.myhome.cx/2551556555554557/Sweet-Memories-Love-So-Sweet-1-by-Steena-Holmes.pdf
    • http://ieuicufioao.myhome.cx/3556555558556557/Sinners-in-the-Hands-of-an-Angry-Church-Finding-a-Better-Way-to-Influence-Our-Culture-by-Dean-Merrill.pdf
    • http://ieuicufioao.myhome.cx/6551559553551553/Love-Next-Door-A-Single-Dad-Romance-and-Romance-Compilation-by-Tia-Siren.pdf
    • http://ieuicufioao.myhome.cx/3555554559550551/-Tis-The-Season-Sweet-Romance-Novelettes-by-D-F-Jones.pdf
    • http://ieuicufioao.myhome.cx/5556551554554555/Nothing-like-the-First-Time-The-Sweet-Romance-Series-1-by-Keren-Hughes.pdf
    • http://ieuicufioao.myhome.cx/4558553554550553/Life-s-Poetry-Poems-About-Life-Family-and-Living-by-Dean-R-Giles.pdf
    • http://ieuicufioao.myhome.cx/3559553559558557/Sweet-and-Spicy-A-Celebration-of-Romance-by-Serena-Sandrin-Tatti.pdf
    • http://ieuicufioao.myhome.cx/9554550551551551/How-to-Write-a-Swoon-Worthy-Sweet-Romance-Novel-by-Victorine-E-Lieske.pdf
    • http://ieuicufioao.myhome.cx/4557555554557555/Sweet-Dreams-A-Musical-Romance-Book-1-by-Emmy-Z-Madrigal.pdf
    • http://ieuicufioao.myhome.cx/2550552558551559/Sweet-Love-at-Bayside-Sweet-with-Heat-Bayside-Summers-1-by-Addison-Cole.pdf
    • http://ieuicufioao.myhome.cx/2551551553554556/Sweet-Jealousy-A-BDSM-Domination-Submission-Romance-Episode-1-by-Morgan-Garrity.pdf
    • http://ieuicufioao.myhome.cx/2552555551555552/A-Christmas-Family-Wish-Sweet-Contemporary-Romance-Novella-by-Helen-Scott-Taylor.pdf
    • http://ieuicufioao.my