Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3b085593013dbd8…

MALICIOUS

PDF

17.5 KB Created: 2020-03-18 22:32:24 +00:00 Authoring application: mPDF 5.7
MD5: 949d3da2fb92f1e99cd7a3a39d713cb7 SHA-1: 6f10480b6edb4bbbe035ceaa0f370f8ace654673 SHA-256: a3b085593013dbd8abc2f6649c484cd0673ae110b1dc00d07e9e9580362fab3a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The heuristic PDF_SEO_LINK_FARM specifically flags this behavior, indicating a likely attempt to drive traffic to a domain hosting potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/352485245524252485242/A-Question-of-Trust-Questions-for-a-Highlander-2-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352485245524252475249/A-Question-of-Love-Questions-for-a-Highlander-1-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/452455240524552415246/A-Question-for-Harry-Questions-for-a-Highlander-4-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/452455240524552415248/A-Question-Worth-Asking-Questions-for-a-Highlander-Book-6-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/252475244524052465244/A-Laird-for-All-Time-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352485245524252485243/My-Heart-s-in-the-Highlands-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352405240524352475245/A-Time-amp-Place-for-Every-Laird-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352405240524352475248/Love-in-the-Time-of-a-Highland-Laird-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352445249524252475245/Question-of-Trust-An-Izzy-McNeil-Mystery-5-by-Laura-Caldwell.pdf
    • http://lwoscmobook.myhome.cx/652415241524652465245/Smart-Trust-How-People-Companies-and-Countries-Are-Prospering-from-High-Trust-in-a-Low-Trust-World-by-Stephen-M-R-Covey.pdf
    • http://lwoscmobook.myhome.cx/252425248524552485241/QBQ-The-Question-Behind-the-Question-Practicing-Personal-Accountability-in-Work-and-in-Life-by-John-G-Miller.pdf
    • http://lwoscmobook.myhome.cx/15241524152425249/The-Highlander-s-Touch-Highlander-3-by-Karen-Marie-Moning.pdf
    • http://lwoscmobook.myhome.cx/25240524352425248/A-Highlander-s-Passion-Highlander-s-Beloved-2-by-Vonnie-Davis.pdf
    • http://lwoscmobook.myhome.cx/152485249524152485247/Highlander-s-Faerie-Highlander-Heat-5-by-Joanne-Wadsworth.pdf
    • http://lwoscmobook.myhome.cx/152475242524552485243/Wedding-the-Highlander-Highlander-3-by-Janet-Chapman.pdf
    • http://lwoscmobook.myhome.cx/85245524452485247/Highlander-for-the-Holidays-Highlander-8-by-Janet-Chapman.pdf
    • http://lwoscmobook.myhome.cx/252435245524852455245/To-Conquer-a-Highlander-Highlander-1-by-Mary-Wine.pdf
    • http://lwoscmobook.myhome.cx/252425247524352425246/Highlander-in-Her-Dreams-Highlander-2-by-Allie-Mackay.pdf
    • http://lwoscmobook.myhome.cx/55243524652465243/Captured-by-the-Highlander-Highlander-1-by-Julianne-MacLean.pdf
    • http://lwoscmobook.myhome.cx/45245524852405242/Claimed-by-the-Highlander-Highlander-2-by-Julianne-MacLean.pdf
    • http://lwoscmobook.myhome.cx/652415241524652465245/Smart-Trust-How-People-Companies-an