Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c64850492f651e5…

MALICIOUS

PDF

19.2 KB Created: 2020-02-05 12:37:36 +00:00 Authoring application: mPDF 5.7
MD5: 8219a2b183c7527d40092c403b649957 SHA-1: bf54c5357e5809a9d67fdc3a4e9590e201415fe4 SHA-256: 9c64850492f651e5e23ed82b8bd4dda69dc7c36697891552654ddda4d08cb22e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary purpose appears to be SEO manipulation or distributing content from the `owlaokopdf.myhome.cx` domain. No scripts were extracted from this sample. The embedded URLs are the main indicators of malicious activity.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/181658169816781638160/On-a-Cold-Road-Tales-of-Adventure-in-Canadian-Rock-by-Dave-Bidini.pdf
    • http://owlaokopdf.myhome.cx/481648161816881668167/The-First-Rock-amp-Roll-Confidential-Report-Inside-the-Real-World-of-Rock-and-Roll-by-Dave-Marsh.pdf
    • http://owlaokopdf.myhome.cx/18160816481688166/I-ll-Mature-When-I-m-Dead-Dave-Barry-s-Amazing-Tales-of-Adulthood-by-Dave-Barry.pdf
    • http://owlaokopdf.myhome.cx/1816181658165816981678162/Upon-This-Rock-by-Dave-Brubeck.pdf
    • http://owlaokopdf.myhome.cx/881698162816481608163/From-Sea-unto-Sea-The-Road-to-Nationhood-1850-to-1910-Canadian-History-Series-4-by-W-G-Hardy.pdf
    • http://owlaokopdf.myhome.cx/181618167816081698163/Hotel-Tales-A-Little-Adventure-and-Some-Unexpected-Tales-by-Hanley-Chew.pdf
    • http://owlaokopdf.myhome.cx/381668167816081658165/Siberiak-My-Cold-War-Adventure-on-the-River-Ob-by-Jenny-Jaeckel.pdf
    • http://owlaokopdf.myhome.cx/1816181608162816881608163/Tales-of-Canadian-Rurality-by-Denn-Thome.pdf
    • http://owlaokopdf.myhome.cx/781678169816181608167/Canadian-Fairy-Tales-by-Cyrus-MacMillan.pdf
    • http://owlaokopdf.myhome.cx/481648161816081608167/The-Heart-Of-Rock-amp-Soul-The-1001-Greatest-Singles-Ever-Made-by-Dave-Marsh.pdf
    • http://owlaokopdf.myhome.cx/981618161816881608167/Canadian-Rock-Music-Groups-Nickelback-Steppenwolf-the-Guess-Who-Heart-Bachman-Turner-Overdrive-Moxy-Cancer-Bats-Lighthouse-Prism-by-Source-Wikipedia.pdf
    • http://owlaokopdf.myhome.cx/481698169816181618162/The-Mystery-Of-Chimney-Rock-Choose-Your-Own-Adventure-5-by-Edward-Packard.pdf
    • http://owlaokopdf.myhome.cx/1816181698164816881658162/Killer-Whale-Rock-A-boy-s-adventure-in-the-Alaskan-wilderness-by-Tim-Garvin.pdf
    • http://owlaokopdf.myhome.cx/281618161816281648165/Johnny-Chinook-Tall-Tales-And-True-From-The-Canadian-West-by-Robert-E-Gard.pdf
    • http://owlaokopdf.myhome.cx/181698161816781698161/One-for-the-Road-An-Outback-Adventure-by-Tony-Horwitz.pdf
    • http://owlaokopdf.myhome.cx/381648162816681638168/A-Road-to-Let-Go-Fallen-Tuesday-4-Brothers-of-Rock-9-by-Karolyn-James.pdf
    • http://owlaokopdf.myhome.cx/481648165816881638162/Star-Wars-Tales-Vol-3-by-Dave-Land.pdf
    • http://owlaokopdf.myhome.cx/481648165816881628164/Star-Wars-Tales-Vol-5-by-Dave-Land.pdf
    • http://owlaokopdf.myhome.cx/381648160816081698168/Star-Wars-Tales-Vol-4-by-Dave-Land.pdf
    • http://owlaokopdf.myhome.cx/481648161816881668163/Louie-Louie-The-History-and-Mythology-of-the-World-s-Most-Famous-Rock-N-Roll-Song-by-Dave-Marsh.pdf
    • http://owlaokopdf.myhome.cx/1816181608162816881608163/Tales-of-C