Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e5b292892e38072…

MALICIOUS

PDF

15.4 KB Created: 2020-03-19 20:50:05 +00:00 Authoring application: mPDF 5.7
MD5: 3cad5bcefafef1302adc413565931a7e SHA-1: 5f5aaeff6f76de524b0b1867719518f7e34ce48e SHA-256: 9e5b292892e38072f135df617e8c474d01acf7220b3dc469c7097c47f2319c0b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'myhome.cx' domain, suggesting a link farm or redirection scheme. While no scripts were extracted, the sheer volume of external links and their unknown reputation indicate a high likelihood of malicious intent, possibly to distribute further malware or phish users. The document body itself is heavily obfuscated and contains repeated URLs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/2877870877873875/The-Four-Seasons-Collection-A-Spring-Affair-A-Summer-Fling-An-Autumn-Crush-A-Winter-Flame-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/3870876872871879/A-Summer-Fling-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/1879877878873872/A-Spring-Affair-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/3876875870873875/Dawn-of-the-Flame-Sea-Flame-Seas-1-by-Jean-Johnson.pdf
    • http://kitasdyu.myhome.cx/2873876877872874/Spring-Fling-by-Sabrina-James.pdf
    • http://kitasdyu.myhome.cx/3877878873872875/Taste-Test-Spring-Fling-by-Sean-Michael.pdf
    • http://kitasdyu.myhome.cx/2877873877873878/Here-Come-the-Boys-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/4877872876870878/A-Summer-Fling-by-Sarah-Madison.pdf
    • http://kitasdyu.myhome.cx/8873872879872/Autumn-s-Flame-The-Graistan-Chronicles-4-by-Denise-Domning.pdf
    • http://kitasdyu.myhome.cx/1879877878873871/The-Birds-And-The-Bees-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/4876877875875875/The-Exception-to-the-Summer-Fling-by-Tara-Brown.pdf
    • http://kitasdyu.myhome.cx/2872879873876875/Avenging-Autumn-Seasons-Change-1-by-D-A-Schneider.pdf
    • http://kitasdyu.myhome.cx/6870876877873/Seasons-of-Our-Lives-Autumn-by-Matilda-Butler.pdf
    • http://kitasdyu.myhome.cx/2871871870874873/Afternoon-Tea-at-the-Sunflower-Caf-by-Milly-Johnson.pdf
    • http://kitasdyu.myhome.cx/4875871871877875/Just-a-Summer-Fling-Lake-Sullivan-1-by-Cate-Cameron.pdf
    • http://kitasdyu.myhome.cx/1871875879875874/Autumn-Getaway-Seasons-of-Love-1-by-Jennifer-Gracen.pdf
    • http://kitasdyu.myhome.cx/4879871873872873/Breath-of-Spring-Seasons-of-the-Heart-4-by-Charlotte-Hubbard.pdf
    • http://kitasdyu.myhome.cx/1873878878875875/Spring-s-Gentle-Promise-Seasons-of-the-Heart-4-by-Janette-Oke.pdf
    • http://kitasdyu.myhome.cx/2870875874876/Spring-s-Renewal-Seasons-of-Sugarcreek-2-by-Shelley-Shepard-Gray.pdf
    • http://kitasdyu.myhome.cx/2873875878874871/Singapore-Fling-Passport-to-Passion-Collection-2-by-Rhian-Cahill.pdf
    • http://kitasdyu.myhome.cx/2872879873876875/Avenging-Autumn-Seasons-Change-1-by-D-A-