Malicious PDF — malware analysis report

Static analysis result for SHA-256 4bcd3b7f7aa845db…

MALICIOUS

PDF

13.7 KB Created: 2020-03-19 20:32:37 +00:00 Authoring application: mPDF 5.7
MD5: 43197c9c518d279488eae4d827a211e5 SHA-1: 01c7550c4b6fdb9beafc8cd38f4c28afda6b4002 SHA-256: 4bcd3b7f7aa845dbf4006c78eba9b7d05160e6d8a806ad7ae73b857f7901f9a6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, indicating a link farm designed to direct users to external content. The heuristic 'PDF_SEO_LINK_FARM' confirms this behavior. No scripts were extracted, and the document body is heavily obfuscated, but the primary intent appears to be driving traffic to the linked PDFs, likely as a lure or to distribute further malicious content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281648164816581618162/A-Question-of-Honor-The-Couriers-1-by-Nita-Abrams.pdf
    • http://owlaokopdf.myhome.cx/481678161816081608168/A-Question-of-Honor-Love-and-Glory-1-by-Lindsay-McKenna.pdf
    • http://owlaokopdf.myhome.cx/781608161816781628162/Nita-Va-Al-Hospital-Nita-Goes-To-Hospital-by-Henriette-Barkow.pdf
    • http://owlaokopdf.myhome.cx/781608161816781668160/Learn-To-Cook-With-Nita-Mehta-by-Nita-Mehta.pdf
    • http://owlaokopdf.myhome.cx/381628164816281648161/Claimed-By-Honor-A-Kurtherian-Gambit-Series-Reclaiming-Honor-2-by-Justin-Sloan.pdf
    • http://owlaokopdf.myhome.cx/681688164816281638160/Honor-1-Protect-Serve-Beat-Burn-Honor-1-by-Bill-Jemas.pdf
    • http://owlaokopdf.myhome.cx/281618169816681698167/Mission-of-Honor-Honor-Harrington-12-by-David-Weber.pdf
    • http://owlaokopdf.myhome.cx/58164816681668162/Honor-Thy-Teacher-Honor-2-by-Teresa-Mummert.pdf
    • http://owlaokopdf.myhome.cx/181678169816381678163/More-Than-Honor-Worlds-of-Honor-1-by-David-Weber.pdf
    • http://owlaokopdf.myhome.cx/281618169816681698164/War-of-Honor-Honor-Harrington-10-by-David-Weber.pdf
    • http://owlaokopdf.myhome.cx/781668165816281658166/Honor-and-Obey-Honor-3-by-Teresa-Mummert.pdf
    • http://owlaokopdf.myhome.cx/281698166816881688166/Honor-amp-Betray-Honor-4-by-Teresa-Mummert.pdf
    • http://owlaokopdf.myhome.cx/181608168816081668169/A-Touch-of-Honor-The-Honor-Trilogy-1-by-J-P-Grider.pdf
    • http://owlaokopdf.myhome.cx/48169816181608163/The-Wagonmaster-by-Nita-Wick.pdf
    • http://owlaokopdf.myhome.cx/781688166816181658168/Project-Lachesis-by-Nita-DeBorde.pdf
    • http://owlaokopdf.myhome.cx/781608161816781618167/The-New-Creative-Artist-by-Nita-Leland.pdf
    • http://owlaokopdf.myhome.cx/781608161816781618163/Suzie-the-Suitcase-by-Nita-Losoponkul.pdf
    • http://owlaokopdf.myhome.cx/881638167816081698166/Solving-Psychic-Attack-by-Nita-Hickok.pdf
    • http://owlaokopdf.myhome.cx/481628165816081648168/The-Ghost-of-Emily-Tapper-by-Nita-Round.pdf
    • http://owlaokopdf.myhome.cx/181668169816781658162/Honor-Honor-1-2-by-Teresa-Mummert.pdf