Malicious PDF — malware analysis report

Static analysis result for SHA-256 20696ff0aeb39dcc…

MALICIOUS

PDF

15.0 KB Created: 2020-03-15 01:03:47 +00:00 Authoring application: mPDF 5.7
MD5: e501803469f22f9c6079eb0f5c55bbfe SHA-1: 7d44511f1f884be268c72baae7a21fdf2c75fe24 SHA-256: 20696ff0aeb39dcc9fff169acb0d8334bccaf2e53284c23849e984e4c21bbe61
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves redirecting users to a domain hosting numerous book-themed PDFs, likely as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/88164816381698161/The-Warrior-s-Maiden-The-Warriors-Series-2-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/88162816681668163/The-Warrior-s-Wife-The-Warrior-Series-1-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/88161816981668163/Lady-in-White-Lady-Series-2-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/281628169816081688162/Awakening-the-Warriors-The-Darkon-Warrior-Series-1-5-by-S-E-Gilchrist.pdf
    • http://owlaokopdf.myhome.cx/481688169816181698168/Lost-Innocents-Servant-of-the-Crown-Mystery-3-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/481658161816781698167/Qualities-of-a-Spiritual-Warrior-Way-of-the-Warrior-Series-by-Graham-Cooke.pdf
    • http://owlaokopdf.myhome.cx/781668165816481638165/The-Warrior-Warriors-1-by-Ty-Patterson.pdf
    • http://owlaokopdf.myhome.cx/28161816081698168/Once-a-Warrior-Warriors-1-by-Karyn-Monk.pdf
    • http://owlaokopdf.myhome.cx/481658164816981668166/Pregnant-by-the-Warrior-Warehaven-1-by-Denise-Lynn.pdf
    • http://owlaokopdf.myhome.cx/181618161816181668167/Warriors-Graystripe-3-Warrior-s-Return-by-Erin-Hunter.pdf
    • http://owlaokopdf.myhome.cx/48166816581618160/Warriors-Graystripe-1-The-Lost-Warrior-by-Erin-Hunter.pdf
    • http://owlaokopdf.myhome.cx/281668163816081608161/Alien-Warrior-Zerconian-Warriors-1-by-Sadie-Carter.pdf
    • http://owlaokopdf.myhome.cx/381688168816281698168/Warrior-s-Pain-Cadi-Warriors-4-by-Stephanie-West.pdf
    • http://owlaokopdf.myhome.cx/481638163816881648168/Warrior-s-Purpose-Cadi-Warriors-5-by-Stephanie-West.pdf
    • http://owlaokopdf.myhome.cx/581678163816581658169/Warrior-Bronze-Gods-and-Warriors-5-by-Michelle-Paver.pdf
    • http://owlaokopdf.myhome.cx/181618161816281668166/Warriors-Graystripe-2-Warrior-s-Refuge-by-Erin-Hunter.pdf
    • http://owlaokopdf.myhome.cx/381668161816081668160/Prophecy-of-the-Female-Warrior-Nephilim-Warriors-1-by-Kate-Young.pdf
    • http://owlaokopdf.myhome.cx/881678165816081688162/Alien-Warrior-s-Baby-Zoran-Warriors-2-by-Luna-Hunter.pdf
    • http://owlaokopdf.myhome.cx/48164816381698169/Warriors-Ravenpaw-s-Path-3-The-Heart-of-a-Warrior-by-Erin-Hunter.pdf
    • http://owlaokopdf.myhome.cx/481658164816281608167/Prophecy-of-the-Female-Warrior-Nephilim-Warriors-1-by-Kate-Young.pdf