Malicious PDF — malware analysis report

Static analysis result for SHA-256 c946c702b8048d25…

MALICIOUS

PDF

17.0 KB Created: 2020-03-20 12:34:57 +00:00 Authoring application: mPDF 5.7
MD5: 3f71ddbb904fa01f6234759ed8db4940 SHA-1: b5c53baf796d009b6be415887c9a1f7b8fbe81b2 SHA-256: c946c702b8048d250fdd6298c66b31a25ad318e16393e1075fd8ab8afb5377e6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, all pointing to the same domain, suggesting a link farm or redirection mechanism. This is indicative of a malicious distribution or phishing campaign. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/6555558550552559/A-Generous-Vision-The-Creative-Life-of-Elaine-de-Kooning-by-Cathy-Curtis.pdf
    • http://ieuicufioao.myhome.cx/6550558552558558/The-Wedding-of-Cathy-and-Irving-A-Cathy-Collection-by-Cathy-Guisewite.pdf
    • http://ieuicufioao.myhome.cx/2555553554553551/Full-Color-Life-How-to-Live-a-Creative-Balanced-Life-by-Margery-Walshaw.pdf
    • http://ieuicufioao.myhome.cx/5556551550559557/The-Baking-Life-of-Amelie-Day-by-Vanessa-Curtis.pdf
    • http://ieuicufioao.myhome.cx/2558557551559553/Embrace-Grace-Welcome-to-the-Forgiven-Life-by-Liz-Curtis-Higgs.pdf
    • http://ieuicufioao.myhome.cx/8559556555556/Another-Life-Altogether-by-Elaine-Beale.pdf
    • http://ieuicufioao.myhome.cx/1550553550554550555/Life-With-the-Movies-Cinematic-Change-amp-Adaptation-by-Curtis-Emde.pdf
    • http://ieuicufioao.myhome.cx/4553556555559556/PHD-to-Ph-D-How-Education-Saved-My-Life-by-Elaine-Richardson.pdf
    • http://ieuicufioao.myhome.cx/1551552554555559551/The-Impact-of-Chaim-Soutine-de-Kooning-Pollock-Dubuffet-Bacon-by-Esti-Dunow.pdf
    • http://ieuicufioao.myhome.cx/1550550550557554558/The-Creative-Habit-Learn-It-and-Use-It-for-Life-by-Twyla-Tharp.pdf
    • http://ieuicufioao.myhome.cx/6555558550552557/La-Seduction-How-the-French-Play-the-Game-of-Life-by-Elaine-Sciolino.pdf
    • http://ieuicufioao.myhome.cx/3559553551551559/Write-Free-Attracting-the-Creative-Life-by-Rebecca-Lawton.pdf
    • http://ieuicufioao.myhome.cx/4559551556553552/Think-Like-an-Artist-How-to-Live-a-Happier-Smarter-More-Creative-Life-by-Will-Gompertz.pdf
    • http://ieuicufioao.myhome.cx/4551553559559558/Positivity-the-Key-to-Life-The-Power-of-Thinking-Positive-by-Cathy-Cavarzan.pdf
    • http://ieuicufioao.myhome.cx/9556558556558554/Abs-of-Steel-Buns-of-Cinnamon-A-Cathy-Collection-by-Cathy-Guisewite.pdf
    • http://ieuicufioao.myhome.cx/3559553553551552/Creative-Is-a-Verb-If-You-re-Alive-You-re-Creative-by-Patti-Digh.pdf
    • http://ieuicufioao.myhome.cx/4550553556552557/The-Creative-Tarot-A-Modern-Guide-to-an-Inspired-Life-by-Jessa-Crispin.pdf
    • http://ieuicufioao.myhome.cx/6554556559554/A-Curious-Mind-Foster-Your-Creative-Potential-For-Better-Life-by-Megan-Coulter.pdf
    • http://ieuicufioao.myhome.cx/5554558556556559/It-s-a-Miserable-Life-Sabrina-the-Teenage-Witch-34-by-Cathy-East-Dubowski.pdf
    • http://ieuicufioao.myhome.cx/3552557556558555/Life-is-Sweet-A-Chocolate-Box-Short-Story-Collection-by-Cathy-Cassidy.pdf
    • http://ieuicufioao.myhome.cx/1550550550557554558/The-Creative-Habit-Learn-It-and-Use-It-for-Life