Malicious PDF — malware analysis report

Static analysis result for SHA-256 16ad7207929283a7…

MALICIOUS

PDF

17.7 KB Created: 2020-03-15 22:20:51 +00:00 Authoring application: mPDF 5.7
MD5: bbbfc6cbc2bff8014c4f6adccdadffd9 SHA-1: 0d69e47c207894cf4d9c852a365a4048d7cb79ef SHA-256: 16ad7207929283a76af95575a45ba8feb530a7ec70a9feb5c4df8ad3255ca85d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the domain 'owlaokopdf.myhome.cx'. This pattern is indicative of a link farm designed to distribute malicious content or engage in SEO poisoning. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/981658169816281638168/The-Hound-of-the-Baskervilles-An-Unabridged-Reading-by-Sir-Derek-Jacobi-by-Arthur-Conan-Doyle.pdf
    • http://owlaokopdf.myhome.cx/281638166816381698163/Luck-and-Faith-Luck-2-by-Ashley-Poch.pdf
    • http://owlaokopdf.myhome.cx/1816181658165816281648163/The-Psychology-of-C-G-Jung-by-Jolande-Jacobi.pdf
    • http://owlaokopdf.myhome.cx/381698166816981668169/Disclosures-in-Scarlet-by-Carl-Jacobi.pdf
    • http://owlaokopdf.myhome.cx/281648161816581638163/Panzer-Commander-The-Memoirs-of-Colonel-Hans-von-Luck-by-Hans-von-Luck.pdf
    • http://owlaokopdf.myhome.cx/481638166816881688166/The-Psychic-World-Of-Derek-Acorah-Discover-How-To-Develop-Your-Hidden-Powers-by-Derek-Acorah.pdf
    • http://owlaokopdf.myhome.cx/181618169816381668167/A-Tale-Of-Manhattan-Return-Of-The-Sacred-Scroll-by-Robert-James-Jacobi.pdf
    • http://owlaokopdf.myhome.cx/481638167816081628168/The-Psychic-Adventures-of-Derek-Acorah-Star-of-TV-s-Most-Haunted-by-Derek-Acorah.pdf
    • http://owlaokopdf.myhome.cx/1816181638169816681668167/The-Hamilton-Jacobi-Theory-In-The-Calculus-Of-Variations-Its-Role-In-Mathematics-And-Physics-by-Hanno-Rund.pdf
    • http://owlaokopdf.myhome.cx/1816181658161816681668163/The-Poetry-of-Derek-Walcott-1948-2013-by-Derek-Walcott.pdf
    • http://owlaokopdf.myhome.cx/18169816781668160/Derek-Jarman-s-Garden-by-Derek-Jarman.pdf
    • http://owlaokopdf.myhome.cx/781688163816581648168/The-Chronicle-of-Pseudo-Turpin-Book-IV-of-the-Liber-Sancti-Jacobi-Codex-Calixtinus-by-Pseudo-Turpin.pdf
    • http://owlaokopdf.myhome.cx/18165816181648166/The-Joy-Luck-Club-by-Amy-Tan.pdf
    • http://owlaokopdf.myhome.cx/981678163816781658168/Luck-of-the-Irish-by-Liz-Gavin.pdf
    • http://owlaokopdf.myhome.cx/481678169816981608162/Some-Luck-by-Jane-Smiley.pdf
    • http://owlaokopdf.myhome.cx/681658166816381698166/Bad-Luck-by-Suzanne-Proulx.pdf
    • http://owlaokopdf.myhome.cx/381668160816681638166/13-For-Luck-by-Agatha-Christie.pdf
    • http://owlaokopdf.myhome.cx/481638165816981678167/Bad-Luck-Officer-by-Suzie-Ivy.pdf
    • http://owlaokopdf.myhome.cx/181618164816481658164/Wish-Me-Luck-by-James-Heneghan.pdf
    • http://owlaokopdf.myhome.cx/381628160816981648164/Good-Luck-Ivy-by-Lisa-Yee.pdf