Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bbf033dd5ea7b41…

MALICIOUS

PDF

16.9 KB Created: 2020-02-06 01:14:42 +00:00 Authoring application: mPDF 5.7
MD5: 22a6fc87cfd485ec61d70393e0f479e6 SHA-1: bc89658d3d42c1d9cbcd80cd2b729a03d07d0ba8 SHA-256: 2bbf033dd5ea7b41fa44efef314dd6429ec29585471b8ccd4a7c093f05659e9b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly flagged this sample as malicious. The primary attack pattern involves directing users to a suspicious domain hosting numerous PDF documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281628166816381668165/Articles-on-Novels-by-Ted-Dekker-Including-Circle-Trilogy-House-Novel-Thr3e-Showdown-Dekker-Novel-Obsessed-Novel-Saint-Novel-Skin-Novel-Blink-Novel-Black-Novel-Red-Novel-White-Novel-Chosen-Novel-by-Hephaestus-Books.pdf
    • http://owlaokopdf.myhome.cx/1816081678164816981638166/Onverwachte-Gasten-In-Gesprek-Met-Gerard-Dekker-Over-Kerk-Godsdienst-En-Cultuur-by-Gerard-Dekker.pdf
    • http://owlaokopdf.myhome.cx/981658167816781618167/A-Kiss-Before-Lying-Last-Kiss-Series-Book-1-by-Bethany-Hensel.pdf
    • http://owlaokopdf.myhome.cx/58169816481668162/Kiss-of-Night-Kiss-Trilogy-1-by-Debbie-Vigui-.pdf
    • http://owlaokopdf.myhome.cx/181698168816581628164/Kiss-of-Death-Kiss-Trilogy-2-by-Debbie-Vigui-.pdf
    • http://owlaokopdf.myhome.cx/381698165816681688162/Kiss-Me-Quick-Kiss-Me-1-by-Margaret-Moore.pdf
    • http://owlaokopdf.myhome.cx/281608161816481668168/The-Widow-s-Kiss-Kiss-1-by-Jane-Feather.pdf
    • http://owlaokopdf.myhome.cx/581608164816381698164/Assassin-s-Kiss-Watcher-s-Kiss-2-by-Sharon-Kay.pdf
    • http://owlaokopdf.myhome.cx/481698169816481648168/A-D-30-A-D-1-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/681648162816181628169/Skin-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/381698162816181678165/Thr3e-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/38168816081658165/Blink-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/88165816081648167/Burn-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/38164816381688160/Thr3e-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/481678162816181668160/Immanuel-s-Veins-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/281618169816081618167/Immanuel-s-Veins-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/48164816981668167/Boneman-s-Daughters-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/481608168816081698162/A-Man-Called-Blessed-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/681628164816581698167/Sangre-de-Emanuel-by-Ted-Dekker.pdf
    • http://owlaokopdf.myhome.cx/381628167816881628164/Kiss-Me-Kiss-of-Death-2-by-L-P-Lovell.pdf
    • http://owlaokopdf.myhome.cx/281608161816481668168/The-Widow-s-Kiss-Kiss-1-b