Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0b44dc4c48c4c47…

MALICIOUS

PDF

13.6 KB Created: 2020-03-15 00:52:42 +00:00 Authoring application: mPDF 5.7
MD5: ff94646421b965e1a94e0d4bfb411080 SHA-1: 9c0e0718b4025b6315e7e08ebfff7205ab5f460c SHA-256: b0b44dc4c48c4c4796bcbefcfd6a2b3258335c3627512462c3ae407b404e022b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on the 'owlaokopdf.myhome.cx' domain. The primary attack pattern appears to be a link farm, likely intended to manipulate search engine results or redirect users to potentially malicious content. No scripts were extracted, and the document body was not parsable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/1816081618162816881658166/A-Warrior-s-Heart-The-Shields-5-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/1816081618162816981658161/A-Forbidden-Temptation-The-Shields-4-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/381648165816381648161/Cowboy-Cross-My-Heart-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/281698169816381608160/Loved-By-a-Warrior-The-Warrior-King-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648167/Dark-Warrior-Warrior-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648168/Legendary-Warrior-Warrior-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/481618167816681668166/Wild-Need-Chiasson-3-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/381688162816581618165/The-Seduced-Rogues-of-Scotland-4-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/481618167816681668167/The-Hunger-Rogues-of-Scotland-2-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/881648165816381648169/Highlander-El-conjuro-olvidado-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/681648165816981678160/Moon-Bound-LaRue-4-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/4816781648169/The-Hero-Sons-of-Texas-1-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/481678160816981638160/Dangerous-Highlander-Dark-Sword-1-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/281678163816881608169/Prince-of-Passion-The-Royal-Chronicles-4-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/381678167816081688168/Wicked-Highlander-Dark-Sword-3-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/181678163816681678168/Dangerous-Highlander-Dark-Sword-1-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/381608161816081628165/Passion-Ignites-Dark-Kings-7-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/281638161816381648163/Dark-Alpha-s-Demand-Reaper-3-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/381678167816081698162/Midnight-s-Lover-Dark-Warriors-2-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/281688161816581688165/Highland-Nights-Druid-s-Glen-2-by-Donna-Grant.pdf
    • http://owlaokopdf.myhome.cx/481678160816981638160/Dangerous-Highlander-Dark-Sword-1-by-Do