Malicious PDF — malware analysis report

Static analysis result for SHA-256 16ad0c63367e18c1…

MALICIOUS

PDF

14.4 KB Created: 2020-03-18 21:25:22 +00:00 Authoring application: mPDF 5.7
MD5: 599c75bf75505bceffaa3d4985264146 SHA-1: d725e3e3964dbc50040a20bbd1f2d5541e001d8b SHA-256: 16ad0c63367e18c1f541c95cee2058ac60e95066b33cccbba3959e28700cafae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, all pointing to external URLs. These links are likely intended to redirect the user to malicious websites. The ML classifier also flagged this PDF as malicious with a high probability.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/681648168816881668164/Renegades-Hotbloods-3-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/681648168816981638164/Venturers-Hotbloods-4-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/481688164816381678163/Beautiful-Monster-2-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/98160816281668163/A-Web-of-Lies-A-Shade-of-Vampire-27-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/88164816281668162/A-Gift-of-Three-A-Shade-of-Vampire-42-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/181688169816481688165/A-Blaze-of-Sun-A-Shade-of-Vampire-5-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/381688167816481608165/The-Secret-of-Spellshadow-Manor-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/1816781658160/A-Trail-of-Echoes-A-Shade-of-Vampire-18-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/581628163816481618166/A-Voyage-of-Founders-A-Shade-of-Vampire-60-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/181688169816481678169/A-Castle-of-Sand-A-Shade-of-Vampire-3-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/4816681688165/An-Empire-of-Stones-A-Shade-of-Vampire-37-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/681648168816881668166/A-City-of-Lies-A-Shade-of-Vampire-55-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/88164816881608167/A-Shield-of-Glass-A-Shade-of-Vampire-49-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/88166816081678163/A-Throne-of-Fire-A-Shade-of-Vampire-40-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/3816181658160/A-Clan-of-Novaks-A-Shade-of-Vampire-25-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/681648168816981638168/A-Clash-of-Storms-A-Shade-of-Vampire-50-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/181628160816881628162/A-Shade-of-Vampire-Boxed-Set-Books-1-amp-2-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/1816981628164/A-Soldier-of-Shadows-A-Shade-of-Vampire-19-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/281688164/A-Spell-of-Time-A-Shade-of-Vampire-10-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/7816181628162/A-Hunt-of-Fiends-A-Shade-of-Vampire-53-by-Bella-Forrest.pdf