Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9f0e55dd76fc38b…

MALICIOUS

PDF

24.4 KB Created: 2020-03-18 21:25:44 +00:00 Authoring application: mPDF 5.7
MD5: 9224af9877d0c63fbd80e81d6cf4c893 SHA-1: a2e26baf8de32ac7e26584c75282f113e2c460f7 SHA-256: b9f0e55dd76fc38be8e5158ab6316440cafc4bd0c5791f348d039c3fb1da960a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, also contains these URLs. This suggests the primary purpose is to direct users to a large collection of external PDF files, likely for SEO manipulation or to host malicious content. No scripts were extracted, and the family is unknown.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solosopos.myhome.cx/4854855855859858/The-Heaven-Trilogy-Heaven-s-Wager-Thunder-of-Heaven-and-When-Heaven-Weeps-by-Ted-Dekker.pdf
    • http://solosopos.myhome.cx/8856853852857/When-Heaven-Weeps-Martyr-s-Song-2-by-Ted-Dekker.pdf
    • http://solosopos.myhome.cx/1851851856852852852/Ferren-amp-The-Invasion-of-Heaven-Book-3-in-The-Heaven-amp-Earth-Trilogy-by-Richard-Harland.pdf
    • http://solosopos.myhome.cx/3853850851852/Heaven-is-for-Real-A-Little-Boy-s-Astounding-Story-of-His-Trip-to-Heaven-and-Back-by-Todd-Burpo.pdf
    • http://solosopos.myhome.cx/4850856854855859/What-If-This-Is-Heaven-How-Our-Cultural-Myths-Prevent-Us-from-Experiencing-Heaven-on-Earth-by-Anita-Moorjani.pdf
    • http://solosopos.myhome.cx/8858851854857851/My-View-from-Heaven-A-Boy-s-Story-of-His-Journey-to-Heaven-and-the-Purpose-of-Life-on-Earth-by-Sarina-Baptista.pdf
    • http://solosopos.myhome.cx/7857851851851859/Heaven-is-for-Real-Deluxe-Edition-A-Little-Boy-s-Astounding-Story-of-His-Trip-to-Heaven-and-Back-by-Todd-Burpo.pdf
    • http://solosopos.myhome.cx/9857850857857/Heaven-is-for-Real-Movie-Edition-A-Little-Boy-s-Astounding-Story-of-His-Trip-to-Heaven-and-Back-by-Todd-Burpo.pdf
    • http://solosopos.myhome.cx/3855858858850855/So-This-Is-Heaven-How-Rescuing-Old-or-Unwanted-Dogs-Provided-a-Touch-of-Heaven-on-Earth-by-Monica-Agnew-Kinnaman.pdf
    • http://solosopos.myhome.cx/3856850852851858/Heaven-Help-Me-Or-Hell-Have-Me-Heaven-Help-Me-1-by-Jolyn-Palliata.pdf
    • http://solosopos.myhome.cx/9851855858855/Heaven-Heaven-1-by-Angela-Johnson.pdf
    • http://solosopos.myhome.cx/9858854855854/Heaven-Hell-From-God-a-Message-of-Faith-A-Young-Boy-s-Experience-of-Heaven-and-Hell-by-Retha-McPherson.pdf
    • http://solosopos.myhome.cx/9857854853857850/Cappuccino-Heaven-A-Life-After-Death-Cappuccino-Heaven-1-by-Michelle-Wright.pdf
    • http://solosopos.myhome.cx/1850850850854859853/Samson-Agonistes-and-Lycidas-quot-The-mind-is-its-own-place-and-in-itself-can-make-a-heaven-of-a-hell-a-hell-of-heaven-quot-by-John-Milton.pdf
    • http://solosopos.myhome.cx/2851858851852853/Thunder-of-Heaven-The-End-2-by-Tim-LaHaye.pdf
    • http://solosopos.myhome.cx/1850857856856/Under-Heaven-Under-Heaven-1-by-Guy-Gavriel-Kay.pdf
    • http://solosopos.myhome.cx/4856857855856853/Heaven-Sent-2-Heaven-Sent-3-amp-4-by-Jet-Mykles.pdf
    • http://solosopos.myhome.cx/3856854858853/Under-Heaven-Under-Heaven-1-by-Guy-Gavriel-Kay.pdf
    • http://solosopos.myhome.cx/3858859855854852/Heaven-s-Shadow-Heaven-s-Shadow-1-by-David-S-Goyer.pdf
    • http://solosopos.myhome.cx/4856856858851850/Cowboy-Heaven-Cowboy-Heaven-1-by-Cheryl-Brooks.pdf
    • http://solosopos.myhome