Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf0bccda3ac2f4c0…

MALICIOUS

PDF

16.9 KB Created: 2020-03-20 17:07:56 +00:00 Authoring application: mPDF 5.7
MD5: 5d3b855371a3f7e3b603333f5e8a150e SHA-1: 032f9f34f871af36a5c8489ea5f9783c5d624c74 SHA-256: bf0bccda3ac2f4c06e1d004bdad2309d1178e2eaed28ea695750656462484b1b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, many of which are structured as numeric slugs followed by book titles, indicating a link farm for SEO manipulation. The primary heuristic firing confirms this, identifying a mass external PDF link farm. The embedded URLs are the main indicators of malicious activity, likely serving as a lure to external malicious content or phishing sites.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/1841848841842842848/Bernie-Magruder-and-the-Disappearing-Bodies-Bessledorf-Mysteries-7-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1846844841849/Bernie-Magruder-and-the-Bats-in-the-Belfry-Bessledorf-Mysteries-9-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1841848841842846844/Bernie-Magruder-and-the-Case-of-the-Big-Stink-Bessledorf-Mysteries-1-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2844840841848849/Shiloh-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1844840842847/Night-Cry-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/4842842845844846/Going-Where-It-s-Dark-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1843841844847845/Alice-in-Lace-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2848847848842844/Sang-Spell-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2847845846846843/The-Agony-of-Alice-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/5844842848849848/Emily-s-Fortune-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1845840849845849/The-Solomon-System-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1843847845840845/Alice-the-Brave-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2847844842841849/Reluctantly-Alice-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/4844848847849846/It-s-Not-Like-I-Planned-It-This-Way-Alice-16-18-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/3847845845848848/Witch-s-Sister-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/1848841841841848/Starting-with-Alice-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2843849840848849/Alice-in-Rapture-Sort-of-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/9848841840843/Shiloh-Trilogy-Boxed-Set-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/2847845845840843/Alice-in-Rapture-Sort-Of-by-Phyllis-Reynolds-Naylor.pdf
    • http://easckaolp.myhome.cx/4848845846841844/Carlotta-s-Kittens-Cat-Pack-3-by-Phyllis-Reynolds-Naylor.pdf