Malicious PDF — malware analysis report

Static analysis result for SHA-256 38f03a92acfd06a9…

MALICIOUS

PDF

19.4 KB Created: 2020-03-19 03:52:22 +00:00 Authoring application: mPDF 5.7
MD5: 79a4263156a6b0b96ef6395ee7626f02 SHA-1: f061f07dad08b2d8b2f57ae18f5b45a55668666d SHA-256: 38f03a92acfd06a9225e511122db2b2279c1f6194d9dcd5076efd1a676d7d86a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a heuristic firing for a link farm, with 32 external PDF links embedded within the document. These links, such as http://owlaokopdf.myhome.cx/681608167816781628168/At-Home-in-the-World-Stories-and-Essential-Teachings-from-a-Monk-s-Life-by-Thich-Nhat-Hanh.pdf, are likely designed to redirect users to malicious content or phishing pages. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/681608167816781628168/At-Home-in-the-World-Stories-and-Essential-Teachings-from-a-Monk-s-Life-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/481648169816881618166/Living-Without-Stress-or-Fear-Essential-Teachings-on-the-True-Source-of-Happiness-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816881608167/Beyond-the-Self-Teachings-on-the-Middle-Way-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/381648166816081698167/Teachings-on-Love-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816781698169/Awakening-of-the-Heart-Essential-Buddhist-Sutras-and-Commentaries-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/381698161816181688168/Going-Home-Jesus-and-Buddha-as-Brothers-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/181648162816381688161/The-World-We-Have-A-Buddhist-Approach-to-Peace-and-Ecology-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816881608169/The-Way-Out-is-in-The-Zen-Calligraphy-of-Thich-Nhat-Hanh-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/481698161816681638166/Silence-The-Power-of-Quiet-in-a-World-Full-of-Noise-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/381698162816081648161/Our-Appointment-with-Life-Sutra-on-Knowing-the-Better-Way-to-Live-Alone-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816681668162/Creating-True-Peace-Ending-Violence-in-Yourself-Your-Family-Your-Community-and-the-World-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816781638165/Our-Appointment-with-Life-Discourse-on-Living-Happily-in-the-Present-Moment-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816681668166/Be-Free-Where-You-Are-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/581668161816381648160/Being-Peace-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/381698161816181678167/The-Sun-My-Heart-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816781638160/A-Pebble-for-Your-Pocket-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681668169816081608166/L-nergie-de-la-pri-re-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/381668163816481638167/How-to-Sit-Mindfulness-Essentials-1-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/781668160816781608164/El-milagro-de-mindfulness-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/681608167816581658163/Zen-Keys-A-Guide-to-Zen-Practice-by-Thich-Nhat-Hanh.pdf
    • http://owlaokopdf.myhome.cx/181648162816381688161/The-Wor