Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa75fc4d61eb633b…

MALICIOUS

PDF

27.5 KB Created: 2020-03-18 22:34:09 +00:00 Authoring application: mPDF 5.7
MD5: 7fb52d8d4f001d89662392974e0b3f45 SHA-1: ed3065f8abefb1fce1285e21a535ce8e9b4bd6af SHA-256: fa75fc4d61eb633bcc4b5bd18b1d0b7526b1f224b49dfde2eed6791153cbf41e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior, indicating a mass external link farm. The URLs themselves are hosted on the domain 'lwoscmobook.myhome.cx', which has no reputation. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/55244524152445244/100-Ways-to-Motivate-Yourself-Change-Your-Life-Forever-by-Steve-Chandler.pdf
    • http://lwoscmobook.myhome.cx/452495248524252485243/Thinking-for-a-Change-11-Ways-Highly-Successful-People-Approach-Life-and-Work-by-John-C-Maxwell.pdf
    • http://lwoscmobook.myhome.cx/352475246524152405245/Begin-with-Yes-A-Short-Conversation-That-Will-Change-Your-Life-Forever-by-Paul-S-Boynton.pdf
    • http://lwoscmobook.myhome.cx/252425246524252405249/Are-You-Ready-To-Take-Charge-Lose-Weight-Get-in-Shape-and-Change-Your-Life-Forever-by-Bob-Harper.pdf
    • http://lwoscmobook.myhome.cx/152495241524352495241/The-9-Intense-Experiences-An-Action-Plan-to-Change-Your-Life-Forever-by-Brian-Vaszily.pdf
    • http://lwoscmobook.myhome.cx/452415245524152445240/Your-Playlist-Can-Change-Your-Life-10-Proven-Ways-Your-Favorite-Music-Can-Revolutionize-Your-Health-Memory-Organization-Alertness-and-More-by-Galina-Mindlin.pdf
    • http://lwoscmobook.myhome.cx/552445241524352425242/12-Simple-Secrets-To-Staying-Motivated-Easy-To-Follow-Everyday-Tips-That-Will-Change-Your-Life-Forever-by-Cary-Bergeron.pdf
    • http://lwoscmobook.myhome.cx/452415244524952405249/Change-Your-Questions-Change-Your-Life-10-Powerful-Tools-for-Life-and-Work-by-Marilee-G-Adams.pdf
    • http://lwoscmobook.myhome.cx/452475240524252415249/Change-Your-Questions-Change-Your-Life-10-Powerful-Tools-for-Life-and-Work-by-Marilee-G-Adams.pdf
    • http://lwoscmobook.myhome.cx/552415241524452475242/Innovation-How-Innovators-Think-Act-and-Change-Our-World-by-Kim-Chandler-McDonald.pdf
    • http://lwoscmobook.myhome.cx/452455246524952465249/Ways-To-Live-Forever-by-Sally-Nicholls.pdf
    • http://lwoscmobook.myhome.cx/35242524152465243/Ways-to-Live-Forever-by-Sally-Nicholls.pdf
    • http://lwoscmobook.myhome.cx/352435246524452405249/Ways-To-Live-Forever-by-Sally-Nicholls.pdf
    • http://lwoscmobook.myhome.cx/952405240524752435243/Three-Minute-Therapy-Change-Your-Thinking-Change-Your-Life-by-Michael-R-Edelstein.pdf
    • http://lwoscmobook.myhome.cx/652405249524452405246/Change-Your-Words-Change-Your-Life-Understanding-the-Power-of-Every-Word-You-Speak-by-Joyce-Meyer.pdf
    • http://lwoscmobook.myhome.cx/852455247524452435249/101-Cost-Effective-Ways-to-Increase-the-Value-of-Your-Home-by-Steve-Berges.pdf
    • http://lwoscmobook.myhome.cx/752405247524852465242/PSYCHOLOGY-CHANGE-YOUR-MIND-CHANGE-YOUR-LIFE-by-Phil-C-Zusak.pdf
    • http://lwoscmobook.myhome.cx/1524152475247524252435247/Memory-Change-Your-Way-of-Thinking-Reference-Point-101-Ways-to-Boost-by-Herbie-Brennan.pdf
    • http://lwoscmobook.myhome.cx/352465241524952485245/Moody-Forever-by-Steve-Oliver.pdf
    • http://lwoscmobook.myhome.cx/2524652445243/The-Coaching-Habit-Say-Less-Ask-More-amp-Change-the-Way-You-Lead-Forever-by-Michael-Bungay-Stanier.pdf
    • http://lwoscmobook.myhome.cx/152495241524352495241/The