Malicious PDF — malware analysis report

Static analysis result for SHA-256 4beed2f0c87c53d7…

MALICIOUS

PDF

15.2 KB Created: 2020-03-19 03:45:21 +00:00 Authoring application: mPDF 5.7
MD5: 57f905f06d8377cf2874a42343d8d97f SHA-1: de212b475c1a0c1324014ee571b603b606c5cf05 SHA-256: 4beed2f0c87c53d7723e3033d4db69fca7a518a497a0a72ca720e5ebf4bfbec1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified as a link farm, all pointing to the domain 'owlaokopdf.myhome.cx'. This technique is often used to distribute malicious content or to engage in SEO poisoning to drive traffic to malicious sites. No scripts were extracted from this sample, and the document body was heavily corrupted, limiting further analysis of the specific lure. The primary attack vector appears to be directing users to external, potentially malicious, PDF files.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/581608164816581628161/Jolted-Conflicted-Encounters-1-by-Alyne-Roberts.pdf
    • http://owlaokopdf.myhome.cx/381608168816581638160/Conflicted-Interest-The-Conflicted-Series-1-by-Ava-Starke.pdf
    • http://owlaokopdf.myhome.cx/381698168816481668168/Conflicted-Men-by-Jason-G-Long.pdf
    • http://owlaokopdf.myhome.cx/481638160816781628162/Lenore-by-Alyne-de-Winter.pdf
    • http://owlaokopdf.myhome.cx/781658167816581608168/Memento-Mori-by-Alyne-de-Winter.pdf
    • http://owlaokopdf.myhome.cx/58169816981668167/The-Lady-in-Yellow-by-Alyne-de-Winter.pdf
    • http://owlaokopdf.myhome.cx/581648166816581648166/Conflicted-Secrets-and-Lies-1-by-M-M-Koenig.pdf
    • http://owlaokopdf.myhome.cx/481658169816181618168/Conflicted-Change-Book-3-by-Heather-Dahlgren.pdf
    • http://owlaokopdf.myhome.cx/481628167816781698161/Mara-The-Roses-of-the-Moon-1-by-Alyne-de-Winter.pdf
    • http://owlaokopdf.myhome.cx/281618164816181658166/The-Shadows-Poppy-Farrell-Mysteries-1-by-Alyne-de-Winter.pdf
    • http://owlaokopdf.myhome.cx/88166816081608160/Conflicted-Love-Needle-s-Kiss-2-by-Lola-Stark.pdf
    • http://owlaokopdf.myhome.cx/981618165816481618163/Nora-Roberts-Circle-Trilogy-CD-Collection-Morrigan-s-Cross-Dance-of-the-Gods-Valley-of-Silence-by-Nora-Roberts.pdf
    • http://owlaokopdf.myhome.cx/681688165816581618164/Bundle-F-te-des-m-res---Nora-Roberts-La-saga-des-O-Hurley-by-Nora-Roberts.pdf
    • http://owlaokopdf.myhome.cx/881688169816381628168/Encounters-with-Art-by-Wolfgang-Felten.pdf
    • http://owlaokopdf.myhome.cx/381688165816881698165/Selected-Stories-of-Morley-Roberts-by-Morley-Roberts.pdf
    • http://owlaokopdf.myhome.cx/281618164816881618160/Encounters-with-the-Unknown-by-Stephen-Young.pdf
    • http://owlaokopdf.myhome.cx/18162816881628166/Close-Encounters-by-Terry-Lawrence.pdf
    • http://owlaokopdf.myhome.cx/181608165816681628169/Brief-Encounters-with-Che-Guevara-Stories-by-Ben-Fountain.pdf
    • http://owlaokopdf.myhome.cx/281688161816881658167/Chance-Encounters-by-Linda-Wells.pdf
    • http://owlaokopdf.myhome.cx/181668167816781648168/Paranormal-Encounters-by-Robbie-Thomas.pdf
    • http://owlaokopdf.myhome.cx/981618165816481618163/Nora-Roberts-Circle-Trilogy-CD-Col