Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ba70bce538471a3…

MALICIOUS

PDF

23.4 KB Created: 2020-03-15 00:52:26 +00:00 Authoring application: mPDF 5.7
MD5: 7fb7ca228ecb40d55ab4432ed1e4dd6d SHA-1: 88b1e8d63c0767ef8e73d27e6a3f6c3042abc9d2 SHA-256: 3ba70bce538471a378d0a7d77195df529a3c4023c2f4d35eca1eb5c61389866e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a significant number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs are likely part of a link farm designed to redirect users to malicious content or phishing sites. No scripts were extracted from this sample, limiting further analysis of its behavior.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/1816181628165816181608169/Angels-Their-Purpose-and-Your-Responsibility-Spiritual-Warrior-s-Basic-Training-Series-by-Dirk-Waren.pdf
    • http://owlaokopdf.myhome.cx/481658161816781698167/Qualities-of-a-Spiritual-Warrior-Way-of-the-Warrior-Series-by-Graham-Cooke.pdf
    • http://owlaokopdf.myhome.cx/1816181628165816181608166/Legalism-Unmasked-New-Revised-Edition-by-Dirk-Waren.pdf
    • http://owlaokopdf.myhome.cx/181678169816281618167/Basic-Training-by-Kurt-Vonnegut.pdf
    • http://owlaokopdf.myhome.cx/1816181658164816181688161/The-Basic-Training-of-Pavlo-Hummel-by-David-Rabe.pdf
    • http://owlaokopdf.myhome.cx/381698166816381628169/Basic-Training-Harlequin-Blaze-238-by-Julie-Miller.pdf
    • http://owlaokopdf.myhome.cx/881688161816281688162/99-Pathways-to-Purpose-Reimagining-Your-Spiritual-Life-by-Austin-Muhs.pdf
    • http://owlaokopdf.myhome.cx/481638163816881648168/Warrior-s-Purpose-Cadi-Warriors-5-by-Stephanie-West.pdf
    • http://owlaokopdf.myhome.cx/381628162816181608161/Soul-DNA-Your-Spiritual-Genetic-Code-Defines-Your-Purpose-by-Jennifer-O-39-Neill.pdf
    • http://owlaokopdf.myhome.cx/381668168816881648165/Soul-DNA-the-Ultimate-Collection-Your-Spiritual-Genetic-Code-Defines-Your-Purpose-by-Jennifer-O-39-Neill.pdf
    • http://owlaokopdf.myhome.cx/88162816681668163/The-Warrior-s-Wife-The-Warrior-Series-1-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/181638162816381618165/Practice-makes-Purpose-Six-Spiritual-Practices-That-Will-Change-Your-Life-and-Transform-Your-Community-by-C-Paul-Schroeder.pdf
    • http://owlaokopdf.myhome.cx/481688160816281668162/Cassidy-Warrior-Princess-in-Training-by-Leigh-Brock.pdf
    • http://owlaokopdf.myhome.cx/481618163816681628164/Warrior-Goddess-Training-Become-the-Woman-You-Are-Meant-to-Be-by-HeatherAsh-Amara.pdf
    • http://owlaokopdf.myhome.cx/481648161816881628165/Warrior-Goddess-Training-Become-the-Woman-You-Are-Meant-to-Be-by-HeatherAsh-Amara.pdf
    • http://owlaokopdf.myhome.cx/881678160816081658163/The-Brain-Warrior-s-Way-Cookbook-Over-100-Recipes-to-Ignite-Your-Energy-and-Focus-Attack-Illness-and-Aging-Transform-Pain-Into-Purpose-by-Tana-Amen.pdf
    • http://owlaokopdf.myhome.cx/481608167816181638166/Angels-are-Real-Angels-Exist-Real-life-encounters-with-Angels-and-Archangels-True-Stories-of-Guardian-Angels-helping-ordinary-people-Angels-are-Real-Angels-Exist-1-by-Tessy-Rawlins.pdf
    • http://owlaokopdf.myhome.cx/781678165816181608168/The-Subtle-Power-of-Spiritual-Abuse-Recognizing-and-Escaping-Spiritual-Manipulation-and-False-Spiritual-Authority-Within-the-Church-by-David-R-Johnson.pdf
    • http://owlaokopdf.myhome.cx/1816081678168816281658169/Basic-Pharmacokinetics-Second-Edition-Pharmacy-Education-Series-by-Mohsen-A-Hedaya.pdf
    • http://owlaokopdf.myhome.cx/1816081628166816781648164/Apple-Pro-Training-Series-Advanced-Editing-Techniques-in-Final-Cut-Pro-5-by-Michael-Wohl.pdf
    • http://owlaokopdf.myhome.cx/381668168816881648165/Soul-DNA-the-Ult