Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2ace4a67a9c7b99…

MALICIOUS

PDF

20.0 KB Created: 2020-02-15 02:45:22 +00:00 Authoring application: mPDF 5.7
MD5: 5f2418dd5049fcba1436678be91a335b SHA-1: 4dd00fb4330c447f61a2e318af3385f6a22feaf3 SHA-256: c2ace4a67a9c7b99d8a568f99eb456c2d23e072af1eba64869c8388800e59214
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents hosted on the same domain. The document body is heavily obfuscated and unreadable, preventing a detailed analysis of its specific content or intent. However, the sheer volume of external links suggests a malicious attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/652405242524152465245/The-Body-s-Place-by-lise-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/752445246524752485247/Your-Body-s-Telling-You-Love-Yourself-The-Most-Complete-Book-on-Metaphysical-Causes-of-Illnesses-amp-Diseases-by-Lise-Bourbeau.pdf
    • http://lwoscmobook.myhome.cx/652425245524652465247/La-Place-d-Annie-Ernaux-Fiche-de-lecture-Comprendre-la-litt-rature-avec-lePetitLitt-raire-fr-by-Lise-Ageorges.pdf
    • http://lwoscmobook.myhome.cx/652425245524652475244/La-Place-d-Annie-Ernaux-Fiche-de-lecture-R-sum-Complet-Et-Analyse-D-taill-e-De-L-oeuvre-by-Lise-Ageorges.pdf
    • http://lwoscmobook.myhome.cx/752445246524952485245/Lise-Haliza-Lise-Haliza-by-LaFlorya-Gauthier.pdf
    • http://lwoscmobook.myhome.cx/652405242524152455249/Geodynamics-by-Donald-L-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524152455245/Exploding-Chippewas-by-Mark-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524252445249/Windfall-The-Cellmate-by-Gary-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524252485248/Malades-d-inqui-tude-by-Hadler-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/352475245524752415240/Pink-Place-A-Lyrical-Journey-to-the-Safe-Place-and-Inner-Drive-Deep-Inside-Every-Child-by-Deb-Simpson.pdf
    • http://lwoscmobook.myhome.cx/1524152445248524352405242/Cap-s-Place-A-Jack-Nolan-Novel-The-Cap-s-Place-Series-1-by-Robert-Tarrant.pdf
    • http://lwoscmobook.myhome.cx/652405242524252445245/Hauntings-The-Varuna-Poems-by-Gerry-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524252485241/People-amp-Places-from-Grimsby-s-Past-by-Dorothy-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524152455241/It-s-Test-Day-Tiger-Turcotte-by-Pansie-Hart-Flood.pdf
    • http://lwoscmobook.myhome.cx/652405242524252435246/Border-Crossings-Words-and-Images-by-Gerry-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524252445240/Public-Services-In-Special-Collections-by-Florence-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524252495244/Rem-des-mortels-et-crime-organis-by-Fernand-Turcotte.pdf
    • http://lwoscmobook.myhome.cx/652405242524152455242/Tiger-Turcotte-Takes-on-the-Know-It-All-by-Pansie-Hart-Flood.pdf
    • http://lwoscmobook.myhome.cx/352465246524652455249/Five-Good-Minutes-in-Your-Body-100-Mindful-Practices-to-Help-You-Accept-Yourself-and-Feel-at-Home-in-Your-Body-by-Jeffrey-Brantley.pdf
    • http://lwoscmobook.myhome.cx/152435245524152405245/Body-Bags-Body-of-Evidence-1-by-Christopher-Golden.pdf