Malicious PDF — malware analysis report

Static analysis result for SHA-256 16d9818792e18ce7…

MALICIOUS

PDF

21.8 KB Created: 2020-03-15 22:24:12 +00:00 Authoring application: mPDF 5.7
MD5: 120727fe30c14c02b722b42067530b9d SHA-1: 374f02f43736d37ef98b9a50377a7d31ab10ac9e SHA-256: 16d9818792e18ce7a5a19c488c86290109e618f0e02ea5147e38a84699fc6a68
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, identified as a link farm. The ML classifier also flagged this document as malicious. The primary purpose appears to be directing users to a large collection of URLs, likely for SEO manipulation or to distribute unwanted content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/481658169816681628161/A-Stallion-No-More---A-Body-Swap-Romance-Gender-Swap-amp-Gender-Transformation-Erotic-Novella-by-Cindel-Sabante.pdf
    • http://owlaokopdf.myhome.cx/281648165816581638161/Gender-Swap-Anita-s-Transgender-Pill-2-An-Accidental-Transformation-by-Sabrina-Jen-Mountford.pdf
    • http://owlaokopdf.myhome.cx/1816081658166816581688167/Gender-Swap-Aphrodisiac-by-Ben-Schrodinger.pdf
    • http://owlaokopdf.myhome.cx/681698160816581618169/Switched-amp-Stuffed-Gender-Swap-5-pack-by-Jezabel-Foxx.pdf
    • http://owlaokopdf.myhome.cx/381678162816581638162/Body-Swap-by-Sylvia-McNicoll.pdf
    • http://owlaokopdf.myhome.cx/781608162816481698167/Catastrophe-Body-Swap-1-by-Katrina-Kahler.pdf
    • http://owlaokopdf.myhome.cx/481678163816481668164/The-Gender-Quest-Workbook-A-Guide-for-Teens-and-Young-Adults-Exploring-Gender-Identity-by-Rylan-Jay-Testa.pdf
    • http://owlaokopdf.myhome.cx/5816281628162/The-Gender-Fall-The-Gender-Game-5-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/5816081608167/The-Gender-War-The-Gender-Game-4-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/6816081618164/The-Gender-End-The-Gender-Game-7-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/4816581688165/The-Gender-Lie-The-Gender-Game-3-by-Bella-Forrest.pdf
    • http://owlaokopdf.myhome.cx/881628167816781688167/Scheherazade-s-Facade-Fantastical-Tales-of-Gender-Bending-Cross-Dressing-and-Transformation-by-Michael-M-Jones.pdf
    • http://owlaokopdf.myhome.cx/281678163816581638165/My-New-Gender-Workbook-A-Step-by-Step-Guide-to-Achieving-World-Peace-Through-Gender-Anarchy-and-Sex-Positivity-by-Kate-Bornstein.pdf
    • http://owlaokopdf.myhome.cx/581618165816281608169/Fragmentation-and-Redemption-Essays-on-Gender-and-the-Human-Body-in-Medieval-Religion-by-Caroline-Walker-Bynum.pdf
    • http://owlaokopdf.myhome.cx/181678160816681638162/48-Hours-An-Erotic-Romance-Novella-by-Jenna-Monroe.pdf
    • http://owlaokopdf.myhome.cx/281648165816581638169/Stripped-of-His-Dignity-Reluctant-Gender-Transformation-Forced-Feminization-Bondage-amp-Submission-Stripped-Series-Book-2-by-Anita-Mandalay.pdf
    • http://owlaokopdf.myhome.cx/381628163816081618164/The-Swap-by-Nancy-Boyarsky.pdf
    • http://owlaokopdf.myhome.cx/481648169816481668162/A-Step-From-the-Edge-MC-Stepbrother-Taboo-Erotic-Romance-Novella-by-Aurora-Sparks.pdf
    • http://owlaokopdf.myhome.cx/481688164816381688166/The-Boyfriend-Swap-by-Meredith-Schorr.pdf
    • http://owlaokopdf.myhome.cx/381638160816681678160/Swap-Meet-by-Lolita-Lopez.pdf