Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7c003b7e970c7a0…

MALICIOUS

PDF

17.4 KB Created: 2020-02-14 23:21:01 +00:00 Authoring application: mPDF 5.7
MD5: 6909c65825a1bab81ef09f02e58880e9 SHA-1: aaf572bd6bff34638877eac4594ecca6b24fa934 SHA-256: f7c003b7e970c7a08a75dd5fc44f7b4dac480d4490cf4d36e8b8f76697b2f058
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates a critical finding related to this SEO link farm. The embedded URLs are likely intended to redirect users to malicious or spam content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/352405245524352445240/Bloodsworn-The-Sherwood-Wolves-Book-4-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152475245524652485245/Shadow-Creatures-The-Sherwood-Wolves-3-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/352415244524152465241/Howl-Series-Books-5-7-Bonus-Book-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152445248524252455246/Wolfsbane-Howl-3-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/252485240524652495244/Wolfsbane-Howl-3-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152445248524352425249/Blood-Moon-Howl-2-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152445248524352415242/Howl-Howl-1-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/252485248524252455249/The-Second-Inspector-Morse-Omnibus-The-Secret-Of-Annexe-3-The-Riddle-Of-Third-Mile-Last-Seen-Wearing-Inspector-Morse-7-6-2-by-Colin-Dexter.pdf
    • http://lwoscmobook.myhome.cx/852405249524652465246/Strong-Arm-Tactics-Wolfe-Pack-Book-1-by-Jody-Lynn-Nye.pdf
    • http://lwoscmobook.myhome.cx/852415241524352495249/The-Way-of-the-Sword-Book-Four-of-The-Somber-Wolves-Saga-by-Matt-Honorato.pdf
    • http://lwoscmobook.myhome.cx/252465244524052425246/The-Order-Of-Wolves-Book-2-Gay-Wolf-Shape-Shifter-Volume-2-by-G-A-Hauser.pdf
    • http://lwoscmobook.myhome.cx/152485248524952475248/Wolves-and-Black-Roses---Immortal-Destiny-Book-3-by-Lorraine-Kennedy.pdf
    • http://lwoscmobook.myhome.cx/45241524052415240/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://lwoscmobook.myhome.cx/252435246524452485246/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://lwoscmobook.myhome.cx/352415242524352485243/Books-for-Kids-Little-Red-Riding-Hood-New-Version-2015-Illustration-Book-Foxes-amp-Wolves-by-Robot-J-.pdf
    • http://lwoscmobook.myhome.cx/352445244524852475244/Among-Wolves-Wolves-of-Llis-1-by-Nancy-K-Wallace.pdf
    • http://lwoscmobook.myhome.cx/152445249524852435249/Wolves-Raised-By-Wolves-4-by-W-A-Hoffman.pdf
    • http://lwoscmobook.myhome.cx/852435248524852425245/Julie-of-the-Wolves-Julie-of-the-Wolves-1-by-Jean-Craighead-George.pdf
    • http://lwoscmobook.myhome.cx/25245524752415248/Raised-by-Wolves-Raised-by-Wolves-1-by-Jennifer-Lynn-Barnes.pdf
    • http://lwoscmobook.myhome.cx/252475242524052425249/Raised-by-Wolves-Raised-by-Wolves-1-by-Jennifer-Lynn-Barnes.pdf
    • http://lwoscmobook.myhome.cx/8524152415243524952