Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd467ba47c6185a9…

MALICIOUS

PDF

14.6 KB Created: 2020-03-18 21:34:35 +00:00 Authoring application: mPDF 5.7
MD5: 3c4062b593c002d8d1eacdc9f9c14f8f SHA-1: 9be6f4ea5d6653719978dfc1aa9a0bda01221faa SHA-256: fd467ba47c6185a9acbc29f6bf0cebc70403ef5aa873fadf26144d7f141f6bdb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to other PDFs hosted on the same domain, suggesting a link farm or a method to distribute malicious content. The document body itself is heavily obfuscated but contains these same URLs, reinforcing their importance. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calistazz.myhome.cx/1860860869860867862/Pastor-June-and-the-Coveters-Pastor-June-2-by-Lee-M-Sapp.pdf
    • http://calistazz.myhome.cx/1860860869860866861/Your-Pastor-My-Husband-Your-Pastor-My-Husband-Book-1-by-B-M-Hardin.pdf
    • http://calistazz.myhome.cx/1860862860867867861/Chasing-June-June-2-by-Shannen-Crane-Camp.pdf
    • http://calistazz.myhome.cx/4860861868863/Finding-June-June-1-by-Shannen-Crane-Camp.pdf
    • http://calistazz.myhome.cx/3868861860867869/June-30th-June-30th-by-Richard-Brautigan.pdf
    • http://calistazz.myhome.cx/8863864860865869/Palme-by-Stefano-Pastor.pdf
    • http://calistazz.myhome.cx/1869862867865867/The-Pastor-s-Wife-by-Elizabeth-von-Arnim.pdf
    • http://calistazz.myhome.cx/1860860869860868866/The-Pastor-s-Heart-by-Desiree-Future.pdf
    • http://calistazz.myhome.cx/8862860863866864/The-Pastor-Evangelist-by-Roger-S-Greenway.pdf
    • http://calistazz.myhome.cx/1860860869862862868/Pastor-as-Person-by-Gary-L-Harbaugh.pdf
    • http://calistazz.myhome.cx/1868868860866866/The-Pastor-s-Wife-by-Jennifer-AlLee.pdf
    • http://calistazz.myhome.cx/9869863862866861/The-Reformed-Pastor-by-Richard-Baxter.pdf
    • http://calistazz.myhome.cx/1860860868869866864/The-Pastor-s-Wife-by-Sabina-Wurmbrand.pdf
    • http://calistazz.myhome.cx/6862867861861869/The-Peace-Making-Pastor-by-Alfred-Poirier.pdf
    • http://calistazz.myhome.cx/1860860869862862862/Success-as-an-Introvert-for-Dummies-by-Joan-Pastor.pdf
    • http://calistazz.myhome.cx/2867861862862860/Lumen-Captain-Martin-Bora-1-by-Ben-Pastor.pdf
    • http://calistazz.myhome.cx/1869864866866867/The-Water-Thief-Aelius-Spartianus-1-by-Ben-Pastor.pdf
    • http://calistazz.myhome.cx/1860860869860866864/The-Pastor-s-Kid-Finding-Your-Own-Faith-and-Identity-by-Barnabas-Piper.pdf
    • http://calistazz.myhome.cx/1860860869861866864/The-Pastor-s-Woman-Three-Weddings-and-a-Reunion-2-by-Jacquelin-Thomas.pdf
    • http://calistazz.myhome.cx/1860860869860866866/Secrets-of-the-Pastor-s-Wife-by-Christina-Ryan-Claypool.pdf