Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd32d27c96339a15…

MALICIOUS

PDF

21.8 KB Created: 2020-03-19 03:45:02 +00:00 Authoring application: mPDF 5.7
MD5: 8ec9b9ce5fb421f657634b46ad0b9b25 SHA-1: 39377561a2e96a1c39cb82c3fb8b6ac53d6ea30a SHA-256: fd32d27c96339a15ec6593f1aad5aa4c15497b56a0dac39ebf586da2f7ee9796
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. These URLs point to various PDF documents, likely to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample. The primary attack pattern appears to be link farming for SEO purposes, potentially as a prelude to a more direct attack.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/881648169816081698160/Frankenstein-Mary-Shelley-The-Modern-Prometheus-Frankenstein-s-Monster-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681668163816581638164/The-Essential-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681648168816581608163/The-Story-of-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618160816081618163/Frankenstein-Galvanised-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581678161816681638163/Frankenstein-o-el-moderno-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581648162816481608160/Frankenstein-or-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781618161816381688164/Frankenstein-narrated-by-Dan-Stevens-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688161816181628166/Frankenstein-Or-the-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681628164816281608162/Frankenstein-o-el-nuevo-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-Original-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681678165816881608164/Frankenstein-Dracula-Dr-Jekyll-And-Mr-Hyde-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581668167816881638167/Frankenstein---playscript-adapted-by-Philip-Pullman-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881638169816681618161/Robert-Andrew-Parker-s-Illustrated-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781658169816781648163/Frankenstein-or-The-Modern-Prometheus-The-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681658161816381658165/Frankenstein-Or-the-Modern-Prometheus-1823-Revolution-amp-Romanticism-1789-1834-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881608167816381648161/Frankenstein-Gothic-Classic---The-Uncensored-1818-Edition-Science-Fiction-Classic-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618164816881688168/The-Life-and-Letters-of-Mary-Wollstonecraft-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658161816281668160/The-Mortal-Immortal-The-Complete-Supernatural-Short-Fiction-of-Mary-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658160816481658167/Mary-and-Maria-by-Mary-Wollstonecraft-amp-Matilda-by-Mary-Shelley-by-Mary-Wollstonecraft.pdf
    • http://owlaokopdf.myhome.cx/781638161816981648160/Frankenstein-or-The-Modern-Prometheus-Companion-Includes-Study-Guide-Complete-Unabridged-Book-Historical-Context-Biography-Character-Index-and-Unabridged-Book-Annotated-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-O