Malicious PDF — malware analysis report

Static analysis result for SHA-256 93df3ce12980068a…

MALICIOUS

PDF

17.4 KB Created: 2020-03-19 20:23:47 +00:00 Authoring application: mPDF 5.7
MD5: 3ad4b04c78b278b338e3e75154210375 SHA-1: cc049089aa823e8e5aa7495f607b5fc736216150 SHA-256: 93df3ce12980068a5afa8e14319e7cf16f357afc4bdb6827ef687796f03ded28
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles, suggesting a potential SEO manipulation scheme or a redirection to malicious content. No scripts were extracted from this sample. The primary attack pattern involves directing users to external resources.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/48168816181608165/How-to-Cheat-a-Dragon-s-Curse-How-to-Train-Your-Dragon-4-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/281698168816681658169/How-to-Cheat-a-Dragon-s-Curse-How-to-Train-Your-Dragon-4-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/78168816281638162/How-To-Ride-A-Dragon-s-Storm-How-to-Train-Your-Dragon-7-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/78169816481678165/How-to-Betray-a-Dragon-s-Hero-How-to-Train-Your-Dragon-11-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/281688165816581608163/How-to-Be-a-Pirate-How-to-train-your-dragon-2-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/48164816581678162/How-to-Be-a-Pirate-How-to-Train-Your-Dragon-2-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/1816181638166816381628165/M-rderische-Drachenfl-che-How-to-Train-Your-Dragon-4-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/281698163816481628166/How-to-Speak-Dragonese-How-to-Train-Your-Dragon-3-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/881678163816481658165/Handbuch-f-r-echte-Helden-How-to-Train-Your-Dragon-6-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/781608166816781618165/N-in-koulutat-lohik-rmeesi-How-to-Train-Your-Dragon-1-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/88161816381698163/The-Day-of-the-Dreader-How-to-Train-Your-Dragon-World-Book-Day-2012-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/1816081658161816381698167/How-to-Be-a-Pirate-Bagaimana-Caranya-Menjadi-Bajak-Laut-How-To-Train-Your-Dragon-2-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/78165816981698168/How-to-Break-a-Dragon-s-Heart-Hiccup-Horrendous-Haddock-III-8-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/281688160816881658160/The-Complete-Book-of-Dragons-A-Guide-to-Dragon-Species-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/381628166816081638168/Dragon-s-Curse-The-Dragon-s-Gift-Trilogy-3-by-Jasmine-Walt.pdf
    • http://owlaokopdf.myhome.cx/481698165816081668160/Dragon-s-Curse-The-Dragon-and-the-Scholar-1-by-H-L-Burke.pdf
    • http://owlaokopdf.myhome.cx/481698163816781688167/How-to-Be-a-Pirate-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/981698164816881638166/Drachenz-hmen-leicht-gemacht-1-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/481668165816181628166/The-Serpent-s-Heir-How-to-Train-Your-Dragon-Graphic-Novels-1-by-Dean-DeBlois.pdf
    • http://owlaokopdf.myhome.cx/981698164816881648166/Drachenz-hmen-leicht-gemacht-8-Flammendes-Drachenherz-by-Cressida-Cowell.pdf