Malicious PDF — malware analysis report

Static analysis result for SHA-256 396a69ed7667e7c7…

MALICIOUS

PDF

18.8 KB Created: 2020-03-18 23:53:12 +00:00 Authoring application: mPDF 5.7
MD5: 5e3c33032db8636d92b70b2a63c65c7a SHA-1: 9832048662fff025893e211e929f4a79a6ef9103 SHA-256: 396a69ed7667e7c7a3e99099280fd3bb17af14811b38a1a5af81ceaefd9edb3d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to a single domain, 'owlaokopdf.myhome.cx'. This is indicative of a link farm or SEO manipulation tactic. The document body, though heavily obfuscated, contains these URLs, suggesting the primary purpose is to redirect users to these external resources. No scripts were extracted, and the file type is PDF, leading to the classification as a potential phishing or malicious content distribution vector.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/981668162816181648166/Beowulf-The-Complete-Story-A-Drama-an-audio-book-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/981688163816481668162/Beowulf-The-Tale-of-Beowulf-Sometime-King-of-the-Folk-of-the-Weder-Geats-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/1816181678166816781648161/The-Tribe---Die-Zuflucht-Freund-oder-Feind-The-Tribe-audio-drama-1-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/781648166816381648167/Beowulf-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/681608168816581608164/Beowulf-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/881638168816381658164/Beowulf-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/581688168816181608166/Beowulf-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/1816081618162816581678164/Beowulf-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/481608164816881638162/Beowulf-The-New-Translation-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/981658169816281638166/Beowulf-And-Related-Readings-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/88168816281668162/Beowulf-A-Verse-Translation-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/681618168816181608168/Beowulf-An-Anglo-Saxon-Epic-Poem-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/781698163816481628163/KOFFI-PT-I-An-E-Book-Short-Story-Drama-Series-by-Mahogani-P-.pdf
    • http://owlaokopdf.myhome.cx/1816181658164816481688162/Lagune-Kursbuch-MIT-Audio-CD-3-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/1816181648166816581638166/Beowulf-Simplified-Includes-Modern-Translation-Study-Guide-Historical-Context-Biography-and-Character-Index-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/281648165816381698164/The-Complete-8-Book-Vampire-Love-Story-Saga-by-H-T-Night.pdf
    • http://owlaokopdf.myhome.cx/181658168816681688165/Unknown-Book-3216233-by-Unknown.pdf
    • http://owlaokopdf.myhome.cx/48161816281648160/The-Word-of-Promise-Complete-Audio-Bible-NKJV-by-Anonymous.pdf
    • http://owlaokopdf.myhome.cx/881628163816481658160/The-Complete-and-Unabridged-Recording-of-The-Lord-of-The-Rings-38-Audio-Cassettes-by-J-R-R-Tolkien.pdf
    • http://owlaokopdf.myhome.cx/1816081648165816981638164/Septimus-Heap-Complete-Collection-Book-One-Magyk-Book-Two-Flyte-Book-Three-Physik-Book-Four-Queste-Book-Five-Syren-Book-Six-Darke-Book-Seven-Fyre-The-Magykal-Papers-The-Darke-Toad-by-Angie-Sage.pdf
    • http://owlaokopdf.myhome.cx/18161