Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c7ea40a9ca71f38…

MALICIOUS

PDF

15.7 KB Created: 2020-03-17 03:53:59 +00:00 Authoring application: mPDF 5.7
MD5: eaee61823befc0f962a49f53469b8f3e SHA-1: e27aa41d63d1d27d190eff3ff67484ee64de8d77 SHA-256: 4c7ea40a9ca71f38dacd22935e36b3c0ed52a48238a10800b68c315d32a5f56e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this document as malicious. The primary attack pattern involves directing users to a domain hosting numerous PDF files, likely to achieve a malicious objective through these external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/58169816281688166/My-Clockwork-Muse-by-D-R-Erickson.pdf
    • http://owlaokopdf.myhome.cx/58165816781678165/The-Infernal-Devices-Clockwork-Angel-Clockwork-Prince-Clockwork-Princess-by-Cassandra-Clare.pdf
    • http://owlaokopdf.myhome.cx/1816181678160816081658164/Chroniken-der-Schattenj-ger-1-3-Clockwork-Angel-1-Clockwork-Prince-2-Clockwork-Princess-3-by-Cassandra-Clare.pdf
    • http://owlaokopdf.myhome.cx/381628169816281688163/The-Girl-and-the-Clockwork-Cat-Clockwork-Enterprises-1-by-Nikki-McCormack.pdf
    • http://owlaokopdf.myhome.cx/181628162816381648163/Clockwork-Lives-Clockwork-Angels-2-by-Kevin-J-Anderson.pdf
    • http://owlaokopdf.myhome.cx/181678169816981698167/The-Girl-and-the-Clockwork-Cat-Clockwork-Enterprises-1-by-Nikki-McCormack.pdf
    • http://owlaokopdf.myhome.cx/181678164816981668166/Becoming-His-Muse---Part-3-Becoming-His-Muse-3-by-K-C-Martin.pdf
    • http://owlaokopdf.myhome.cx/1816181668163816481608169/Mission-Clockwork-Band-2-Mission-Clockwork-Angriff-aus-der-Tiefe-by-Arthur-Slade.pdf
    • http://owlaokopdf.myhome.cx/181678164816981668169/Becoming-His-Muse-Becoming-His-Muse-1-by-K-C-Martin.pdf
    • http://owlaokopdf.myhome.cx/28165816381678165/Clockwork-Heart-Clockwork-Heart-1-by-Dru-Pagliassotti.pdf
    • http://owlaokopdf.myhome.cx/381628163816981668163/The-Clockwork-Man-by-E-V-Odle.pdf
    • http://owlaokopdf.myhome.cx/481648165816481608164/Break-It-by-Ben-Muse.pdf
    • http://owlaokopdf.myhome.cx/281638164816181638166/Clockwork-Pirate-by-Lyn-Gala.pdf
    • http://owlaokopdf.myhome.cx/381678167816681688167/The-Muse-by-Suzie-Carr.pdf
    • http://owlaokopdf.myhome.cx/381678161816281648162/The-Muse-by-Renee-Lee-Fisher.pdf
    • http://owlaokopdf.myhome.cx/181608165816981688163/Muse-Unexpected-by-V-C-Birlidis.pdf
    • http://owlaokopdf.myhome.cx/381698161816681698161/Muse-of-Fire-by-Dan-Simmons.pdf
    • http://owlaokopdf.myhome.cx/381628168816581668162/His-Muse-by-Twyla-Turner.pdf
    • http://owlaokopdf.myhome.cx/481648163816481608162/Consuming-the-Muse-by-AstridL.pdf
    • http://owlaokopdf.myhome.cx/981608163816781698165/The-Muse-by-Jessie-Burton.pdf