Malicious PDF — malware analysis report

Static analysis result for SHA-256 23a98a86ecd80f8e…

MALICIOUS

PDF

16.8 KB Created: 2020-03-19 03:59:12 +00:00 Authoring application: mPDF 5.7
MD5: 2186f039e35f2c6e1d1fa09bff532ba4 SHA-1: d1f39a46fa96db768bdfaf227a20bce176058550 SHA-256: 23a98a86ecd80f8ee84b14bf1f1689fde2a54721d9258aec99cc6128aeb49b23
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the PDF's purpose is to direct users to a malicious website. The ML classifier strongly supports this assessment. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/981698160816381648167/Das-Geheimnis-der-Feentochter-I-II-eBundle-by-Maria-M-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/981698160816381648166/Kiss-of-Fay---Das-Geheimnis-der-Feentochter-II-by-Maria-M-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/1816081628166816481678167/Kiss-of-Fay-by-Maria-M-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/1816181658160816181628167/Unerh-rte-Skandale---unerwartete-Sehnsucht-eBundle-by-Dorothy-Elbury.pdf
    • http://owlaokopdf.myhome.cx/981618169816781628164/Unversch-mt-amp-reich---leidenschaftliche-Milliard-re-2-eBundle-by-Catherine-Mann.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816581608160/Through-My-Veins-Second-Story-4-by-J-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/681698169816681608160/The-Grave-Marker-by-Don-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/681668167816481628160/Gard-by-Dominique-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/481628163816381648161/Massage-for-Lovers-by-Nitya-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/181608168816081678163/Night-Wave-by-Todd-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816481688168/The-Billionaire-s-Offer-by-Lila-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/181678167816081638167/Pirate-s-Mistress-by-Marianne-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816581618167/Eternal-Embrace-by-Marianne-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816481698169/The-Scars-of-Jocasta-Lacroix-by-Jack-Harvey.pdf
    • http://owlaokopdf.myhome.cx/881618167816681648160/CHUM-Le-une-trag-die-qu-b-coise-by-Robert-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/281688161816881698169/Perhaps-I-ve-Said-Too-Much-A-Great-Big-Book-of-Messing-with-People-by-Rodney-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/38160816281678169/Maria-s-Duck-Tales-Wildlife-Stories-from-My-Garden-by-Maria-Daddino.pdf
    • http://owlaokopdf.myhome.cx/1816181618167816581698164/Guy-Lacroix-Sammelband-Auf-der-Jagd-nach-dem-Rosenkranzm-rder-amp-In-den-Klauen-des-Metamorphen-by-Simone-Keil.pdf
    • http://owlaokopdf.myhome.cx/981608167816381668167/Das-Geheimnis-von-Inselort-by-Winifred-Well.pdf
    • http://owlaokopdf.myhome.cx/681618161816981698164/Mes-250-Aires-de-services-et-Parkings-pour-camping-car-en-Italie-Centrale-Latium-Ombrie-Toscane-by-Annette-Lacroix.pdf