Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3aa883759a898cd…

MALICIOUS

PDF

20.1 KB Created: 2020-02-06 00:14:07 +00:00 Authoring application: mPDF 5.7
MD5: 7526977ed88285c7c15eb09a9aa18562 SHA-1: 17c9c6ce7531d4531fda44bb043184bff3222a07 SHA-256: c3aa883759a898cd701108c2376caa5e7393ff0fe4d21f3ac862452c40ecfa07
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external PDF documents, suggesting a link farm or a distribution mechanism for further malicious content. The DOC BODY section confirms the presence of these URLs, indicating a likely intent to redirect users to potentially harmful websites.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/381678163816481608168/Presents-Passion-amp-Proposals-The-Billionaire-s-Christmas-Gift-One-Christmas-Night-in-Venice-Snowbound-with-the-Millionaire-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281608162816981688169/Burning-Obsession-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281608163816281698161/Velvet-Promise-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/481698160816281688161/The-Failed-Marriage-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/481698160816581648162/The-Innocent-Virgin-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/981618161816981698167/Z-rtliche-Eroberung-in-Paris-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281658164816081648168/Bryn-Dragon-Hearts-3-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281608163816481618163/Pregnant-with-the-Billionaire-s-Baby-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/481608168816381648164/At-the-Duke-s-Service-The-Notorious-St-Claires-0-5-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/781668168816181638165/The-Fiance-Fix-Memilih-Calon-Suami-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/781608167816481638163/Wife-by-Contract-Mistress-by-Demand-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/181678161816581628164/A-Touch-of-Notoriety-Buenos-Aires-Nights-2-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/481678160816981608161/Lady-Arabella-s-Scandalous-Marriage-The-Notorious-St-Claires-4-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281608163816381638164/Passion-amp-the-Past-Hearts-of-Fire-3-by-Miranda-Lee.pdf
    • http://owlaokopdf.myhome.cx/381678163816281618165/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas-Engagement-A-Bride-for-Christmas-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/281628165816181658168/A-Puppy-for-Christmas-On-the-Secretary-s-Christmas-List-The-Soldier-the-Puppy-and-Me-The-Patter-of-Paws-at-Christmas-by-Carole-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/181678168816081618169/The-Greatest-Traitor-The-Life-of-Sir-Roger-Mortimer-Ruler-of-England-1327-1330-by-Ian-Mortimer.pdf
    • http://owlaokopdf.myhome.cx/781608167816381688168/Arabel-Mortimer-and-the-Escaped-Black-Mamba-Arabel-and-Mortimer-2-by-Joan-Aiken.pdf
    • http://owlaokopdf.myhome.cx/781608167816481658165/Mortimer-Keene-Ghosts-on-the-Loose-Mortimer-Keene-2-by-Tim-Healey.pdf
    • http://owlaokopdf.myhome.cx/681678167816581618164/Maigrir-avec-la-lune-Faites-fondre-vos-kilos-superflus-en-suivant-les-cycles-lunaires-de-Carole-Berger-by-Carole-Berger.pdf
    • http://owlaokopdf.myhome.cx/781608167816481638163/Wife-by-Contra