Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0e40148450bb6d8…

MALICIOUS

PDF

16.2 KB Created: 2020-03-18 22:15:43 +00:00 Authoring application: mPDF 5.7
MD5: 795bfde4d61fab47bbb10e761f416fae SHA-1: ec0add8070de99f60a9abc5933c4b4519a654ce8 SHA-256: c0e40148450bb6d8e9b93eb9e943d88250771c42b4a5600a1a96d3886d176862
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, indicating a large number of embedded URLs. These URLs, such as http://ieuicufioao.myhome.cx/2555559550557555/Kissed-by-an-Angel-The-Power-of-Love-Soulmates-Kissed-by-an-Angel-1-3-by-Elizabeth-Chandler.pdf, are likely used to redirect users to malicious content. No scripts were extracted from this sample, limiting further analysis of its specific payload delivery mechanism.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2555559550557555/Kissed-by-an-Angel-The-Power-of-Love-Soulmates-Kissed-by-an-Angel-1-3-by-Elizabeth-Chandler.pdf
    • http://ieuicufioao.myhome.cx/3552559558554/Kissed-by-an-Angel-The-Power-of-Love-Soulmates-Kissed-by-an-Angel-1-3-by-Elizabeth-Chandler.pdf
    • http://ieuicufioao.myhome.cx/1550553555552550555/Janice-Van-Cleave-s-Scientists-Through-the-Ages-by-Janice-VanCleave.pdf
    • http://ieuicufioao.myhome.cx/8554559555552554/The-Red-Geraniums-by-J-Schlenker.pdf
    • http://ieuicufioao.myhome.cx/8554559554554558/Hardy-Geraniums-by-Peter-Yeo.pdf
    • http://ieuicufioao.myhome.cx/8554559555558555/My-Little-White-Geraniums-by-Brandon-Berntson.pdf
    • http://ieuicufioao.myhome.cx/8554559552559550/Geraniums-and-Pelargoniums-by-John-Feltwell.pdf
    • http://ieuicufioao.myhome.cx/8554559555559553/Geraniums-Lilacs-and-Rosebuds-by-Antoinette-Harvey.pdf
    • http://ieuicufioao.myhome.cx/8554559555552552/A-Persistence-of-Geraniums-by-John-Linwood-Grant.pdf
    • http://ieuicufioao.myhome.cx/8554559554555557/Surprised-Pink-Geraniums-A-Memoir-by-Pat-Brown.pdf
    • http://ieuicufioao.myhome.cx/3557559558551/Demon-Kissed-Demon-Kissed-1-by-H-M-Ward.pdf
    • http://ieuicufioao.myhome.cx/8554559554555558/Cabbages-and-Geraniums-Memories-of-the-Holocaust-by-Valerie-Furth.pdf
    • http://ieuicufioao.myhome.cx/8554559553554552/Hardy-Geraniums-Wisley-Handbooks-by-David-Hibberd.pdf
    • http://ieuicufioao.myhome.cx/1559558558555557/Daisies-are-Forever-by-Sydell-Voeller.pdf
    • http://ieuicufioao.myhome.cx/1554555557554553/Dancing-on-Daisies-by-Cate-Herndon.pdf
    • http://ieuicufioao.myhome.cx/1550558557552552/Paper-Daisies-by-Mina-Martinelli.pdf
    • http://ieuicufioao.myhome.cx/8554559555559555/Growing-Pelargoniums-and-Geraniums-A-Complete-Guide-by-Beryl-Stockton.pdf
    • http://ieuicufioao.myhome.cx/1559559552551555/House-of-Lost-Daisies-by-Megan-Weiss.pdf
    • http://ieuicufioao.myhome.cx/9553552550554553/The-Goddess-of-Buttercups-amp-Daisies-by-Martin-Millar.pdf
    • http://ieuicufioao.myhome.cx/5550550551552552/House-of-Lost-Daisies-by-Megan-Weiss.pdf
    • http://ieuicufioao.m