Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfe809a49af129a6…

MALICIOUS

PDF

17.4 KB Created: 2020-03-17 03:52:51 +00:00 Authoring application: mPDF 5.7
MD5: 42039651fe0368c50c36ac3174902bd8 SHA-1: fca8fcb5d6a6b4c1d28ca74ecec728d434bee85e SHA-256: bfe809a49af129a65abbc9fbad2a4efc4cde719079026c8dce5b578a3d592292
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on the domain 'owlaokopdf.myhome.cx'. This is indicative of a link farm or a mechanism to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/381668162816481658164/The-Forever-Whale-by-Sarah-Lean.pdf
    • http://owlaokopdf.myhome.cx/98169816281658164/2-Second-Lean-How-to-Grow-People-and-Build-a-Fun-Lean-Culture-by-Paul-A-Akers.pdf
    • http://owlaokopdf.myhome.cx/681678165816881658166/Lean-Six-SIGMA-for-Service-How-to-Use-Lean-Speed-and-Six-SIGMA-Quality-to-Improve-Services-and-Transactions-by-Michael-L-George.pdf
    • http://owlaokopdf.myhome.cx/281698160816981698166/Homeless-by-Christopher-Lee-Cousino.pdf
    • http://owlaokopdf.myhome.cx/281608165816981648160/Come-When-Called-Come-When-Called-1-7-by-Piper-Trace.pdf
    • http://owlaokopdf.myhome.cx/98167816081628160/A-Boy-Called-Bat-A-Boy-Called-Bat-1-by-Elana-K-Arnold.pdf
    • http://owlaokopdf.myhome.cx/781698165816181688162/Homeless-Rats-by-Ahmed-Fagih.pdf
    • http://owlaokopdf.myhome.cx/381618161816681638163/Marching-Bands-Are-Just-Homeless-Orchestras-by-Tim-Siedell.pdf
    • http://owlaokopdf.myhome.cx/681638168816681608165/Piers-of-the-Homeless-Night-by-Jack-Kerouac.pdf
    • http://owlaokopdf.myhome.cx/78163816681658160/My-Dog-Always-Eats-First-Homeless-People-and-Their-Animals-by-Leslie-Irvine.pdf
    • http://owlaokopdf.myhome.cx/381618166816381668169/The-Silent-Miaow-A-Manual-for-Kittens-Strays-and-Homeless-Cats-by-Paul-Gallico.pdf
    • http://owlaokopdf.myhome.cx/381618166816081688163/Rescue-Renew-Rehome-A-Practical-Guide-To-Adopting-America-s-8-Million-Homeless-Animals-by-Steve-Monahan.pdf
    • http://owlaokopdf.myhome.cx/381698166816681608165/My-So-Called-Superpowers-My-So-Called-Superpowers-1-by-Heather-Nuhfer.pdf
    • http://owlaokopdf.myhome.cx/781608162816281618165/OUR-HOME-at-IKEA-Or-How-a-desparate-Homeless-Family-moves-into-Ikea-by-Dzoan-Nguyen-Tran.pdf
    • http://owlaokopdf.myhome.cx/481698160816581688166/Lean-on-Me-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/1816181608162816781618168/Lean-Roadmap-by-Howard-Thomes.pdf
    • http://owlaokopdf.myhome.cx/1816181688160816581688166/A-Lean-Against-the-Wheel-by-Egon-H-E-Lass.pdf
    • http://owlaokopdf.myhome.cx/781608162816181678166/Lean-management-by-Christian-Hohmann.pdf
    • http://owlaokopdf.myhome.cx/681608163816081628160/UX-for-Lean-Startups-by-Laura-Klein.pdf
    • http://owlaokopdf.myhome.cx/1816181698162816381608161/Lean-Manufacturing-by-William-M-Feld.pdf
    • http://owlaokopdf.myhome.cx/78163816681658160/My-Dog-Always-Eats-First-Homeless-People-and-Their-Animals-by-Leslie-Irvine.p