Malicious PDF — malware analysis report

Static analysis result for SHA-256 5200941efe0c2478…

MALICIOUS

PDF

17.0 KB Created: 2020-03-15 00:54:34 +00:00 Authoring application: mPDF 5.7
MD5: e54abbf95b27c0c57a8fb9d2f02ef38e SHA-1: a33d6de71d38c7c84cd79fa3f437b8f5cfdeb9a3 SHA-256: 5200941efe0c2478e0967b0d8a533ebebb6f79fef8f1ef9728de8566f9220adb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links point to various book titles hosted on the 'owlaokopdf.myhome.cx' domain. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be a link farm designed to drive traffic to potentially malicious or spam content, masquerading as legitimate book downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281618164816381618164/Whispers-on-the-Wind-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648166/Taken-By-Storm-Highlander-Duo-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648163/Tame-My-Wild-Touch-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/281658161816881668163/Wedding-Spell-Witch-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/78167816281638162/Under-the-Highlander-s-Spell-Sinclare-Brothers-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/281678169816781618169/Return-of-the-Rogue-Sinclare-Brothers-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/281678169816781638161/The-Highlander-s-Forbidden-Bride-Sinclare-Brothers-4-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/181658162816981628169/The-Fields-of-Bannockburn-A-Novel-of-Christian-Scotland-from-Its-Origins-to-Independence-by-Donna-Fletcher-Crow.pdf
    • http://owlaokopdf.myhome.cx/481618164816581658160/The-King-s-Executioner-Pict-King-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/281698169816381608160/Loved-By-a-Warrior-The-Warrior-King-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648168/Legendary-Warrior-Warrior-1-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081638168/The-Bewitching-Twin-Twin-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648162816081648167/Dark-Warrior-Warrior-2-by-Donna-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/981688161816981668160/Fletcher-and-the-Great-Raid-Fletcher-Series-Book-4-by-John-Drake.pdf
    • http://owlaokopdf.myhome.cx/881628164816681618163/Phylaster-Or-Loue-Lyes-a-Bleeding-Acted-at-the-Globe-by-His-Maiesties-Seruants-Written-by-Brace-Francis-Baymont-and-Iohn-Fletcher-1620-by-John-Fletcher.pdf
    • http://owlaokopdf.myhome.cx/381648161816481618166/The-Family-Fletcher-Takes-Rock-Island-Family-Fletcher-2-by-Dana-Alison-Levy.pdf
    • http://owlaokopdf.myhome.cx/381628163816681678161/The-Last-Buccaneer-by-Lynn-Erickson.pdf
    • http://owlaokopdf.myhome.cx/18163816181678166/The-Misadventures-of-the-Family-Fletcher-Family-Fletcher-1-by-Dana-Alison-Levy.pdf
    • http://owlaokopdf.myhome.cx/281628165816681608161/An-Unlikely-Buccaneer-The-First-Goony-by-Allan-R-Luna.pdf
    • http://owlaokopdf.myhome.cx/481648164816781678166/The-Buccaneer-s-Apprentice-The-Cassaforte-Chronicles-2-by-V-Briceland.pdf
    • http://owlaokopdf.myhome.cx/481618164816581658160/The-King-s-Exe