Malicious PDF — malware analysis report

Static analysis result for SHA-256 12f8d7ae40e9248c…

MALICIOUS

PDF

18.8 KB Created: 2020-03-18 21:26:16 +00:00 Authoring application: mPDF 5.7
MD5: 6bbb86ce37ac7268f759e9893eb4c82a SHA-1: 2c909cedb17b67650222b1e3af2d385d2fa4fafd SHA-256: 12f8d7ae40e9248c0772ccd75556257e2f1f7b2c1b82741adf0a7bbe7f1163cf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs pointing to external PDF files on a suspicious domain, indicative of a link farm or SEO poisoning attack. The ML classifier also flagged this document as malicious with high confidence. The primary attack pattern involves directing users to a large collection of external resources, likely to manipulate search engine rankings or distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/1816081678168816381688169/Gotthold-s-Emblems-Or-Invisible-Things-Understood-by-Things-That-Are-Made-by-Christian-Scriver.pdf
    • http://owlaokopdf.myhome.cx/381648163816381628167/50-Things-to-Know-To-Enjoy-An-All-Inclusive-Resort-A-Travelers-Guide-50-Things-to-Know-Vacation-Series-by-Lisa-M-Rusczyk.pdf
    • http://owlaokopdf.myhome.cx/581618166816481668169/The-Things-We-Lose-The-Things-We-Leave-Behind-by-Billy-O-39-Callaghan.pdf
    • http://owlaokopdf.myhome.cx/381628161816781678161/50-Things-To-Know-To-Live-a-Stress-Free-Life-Reduce-Stress-and-Relax-50-Things-to-Know-Healthy-Living-Series-by-Lisa-M-Rusczyk.pdf
    • http://owlaokopdf.myhome.cx/281648166816581658160/Things-Kept-Things-Left-Behind-by-Jim-Tomlinson.pdf
    • http://owlaokopdf.myhome.cx/181678165816181638162/Dark-Dreams-and-Dead-Things-Dead-Things-2-by-Martina-McAtee.pdf
    • http://owlaokopdf.myhome.cx/181648167816181678169/All-Good-Things-Absolved-Good-Things-3-by-Alannah-Carbonneau.pdf
    • http://owlaokopdf.myhome.cx/181648166816981668168/All-Good-Things-Good-Things-1-by-Alannah-Carbonneau.pdf
    • http://owlaokopdf.myhome.cx/48167816281668164/Bright-Young-Things-Bright-Young-Things-1-by-Anna-Godbersen.pdf
    • http://owlaokopdf.myhome.cx/881658160/Tiny-Pretty-Things-Tiny-Pretty-Things-1-by-Sona-Charaipotra.pdf
    • http://owlaokopdf.myhome.cx/1816081688166816881628162/Roller-Coaster-Science-50-Wet-Wacky-Wild-Dizzy-Experiments-about-Things-Kids-Like-Best-Wet-Wacky-Wild-Dizzy-Experiments-About-Things-Kids-Like-Best-by-Jim-Wiese.pdf
    • http://owlaokopdf.myhome.cx/481648167816381658169/Things-I-ll-Never-Say-by-M-J-O-39-Shea.pdf
    • http://owlaokopdf.myhome.cx/481658169816681688163/Things-I-Must-Have-Known-by-A-B-Spellman.pdf
    • http://owlaokopdf.myhome.cx/381678168816381678169/All-The-Pretty-Things-by-Rae-D-Magdon.pdf
    • http://owlaokopdf.myhome.cx/281618169816681618161/The-Things-We-Promise-by-J-C-Burke.pdf
    • http://owlaokopdf.myhome.cx/48165816581648168/10-Things-to-Do-Before-I-Die-by-Daniel-Ehrenhaft.pdf
    • http://owlaokopdf.myhome.cx/381658166816981678161/Can-Such-Things-Be-by-Ambrose-Bierce.pdf
    • http://owlaokopdf.myhome.cx/181628167816981658165/Bad-Things-by-Tamara-Thorne.pdf
    • http://owlaokopdf.myhome.cx/781658167816981648161/Consider-These-Things-by-Joel-Belz.pdf
    • http://owlaokopdf.myhome.cx/181618164816381628164/The-Evidence-Of-Things-Not-Seen-by-W-H-Murray.pdf