Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b5cbfa0cb10f6f1…

MALICIOUS

PDF

17.2 KB Created: 2020-03-17 03:53:46 +00:00 Authoring application: mPDF 5.7
MD5: d7c73599e95dad3dcdd603c54982e355 SHA-1: 5a4a7e6e028ef1d227f53d7fd18bb064c553f54a SHA-256: 5b5cbfa0cb10f6f15f70c84ceb980d0fe363d8a0d57d7ea59eaf074eaad5289e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file exhibits characteristics of a link farm, embedding a large number of external URLs that appear to be disguised as book downloads. The primary heuristic indicates a mass external PDF link farm, and the ML classifier strongly flagged it as malicious. The embedded URLs likely lead to a malicious site designed to trick users into downloading further malware or engaging in phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/38162816181628163/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/181688163816481648165/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/48164816981628168/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/581638168816681618165/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/381648167816481648169/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/78160816781658168/Vampire-Academy-Vampire-Academy-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/9816681638162/Vampire-Academy-The-Graphic-Novel-Vampire-Academy-The-Graphic-Novel-1-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/78169816581638168/Last-Sacrifice-Vampire-Academy-6-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/281648169816881608161/Last-Sacrifice-Vampire-Academy-6-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/88168816481638166/Last-Sacrifice-Vampire-Academy-6-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/481608166816081698166/Shadow-Kiss-Vampire-Academy-3-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/481608166816081698168/Blood-Promise-Vampire-Academy-4-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/18160816881638160/Blood-Promise-Vampire-Academy-4-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/481668160816581658166/Spirit-Bound-Vampire-Academy-5-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/58165816581648161/Blood-Promise-Vampire-Academy-4-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/281608169816781668164/Shadow-Kiss-Vampire-Academy-3-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/181648167816881648163/Shadow-Kiss-The-Graphic-Novel-Vampire-Academy-The-Graphic-Novel-3-by-Richelle-Mead.pdf
    • http://owlaokopdf.myhome.cx/481638167816181658162/Frostbite-Dimitri-s-POV-Vampire-Academy-2-1-by-Shelby-Petrie.pdf
    • http://owlaokopdf.myhome.cx/1816181638166816881648167/Livros-de-Fantasia-Alice-No-Pais-Das-Maravilhas-Vampire-Academy-as-Aventuras-de-Pinoquio-Literatura-Fantastica-the-Lightning-Thief-Eragon-by-Source-Wikipedia.pdf
    • http://owlaokopdf.myhome.cx/981688164816981698160/The-Academy-Making-of-a-Ruler-The-Eagle-King-s-Academy-1-by-C-C-Mon-.pdf