Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c15baa2ae159852…

MALICIOUS

PDF

22.8 KB Created: 2020-03-09 07:38:48 +00:00 Authoring application: mPDF 5.7
MD5: abd6de3b94969a182d28688c09925a27 SHA-1: cb0f8573f3ff4f1c42af264223ab6335965dafaa SHA-256: 5c15baa2ae159852255b341e85c12781b2ee19518360a040c9ae6460ca93cc77
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. These URLs likely lead to malicious content or phishing pages. The ML classifier also strongly indicated maliciousness. The primary attack pattern observed is the distribution of a link farm to redirect users to potentially harmful external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281658165816681628160/Harnessing-Earth-Magic-A-Witch-s-Guide-to-Elemental-Magic-Elemental-Witchcraft-and-Magic-Book-3-by-Viivi-James.pdf
    • http://owlaokopdf.myhome.cx/281658165816881658164/Harnessing-Air-Magic-A-Witch-s-Guide-to-Elemental-Magic-Elemental-Witchcraft-and-Magic-Book-1-by-Viivi-James.pdf
    • http://owlaokopdf.myhome.cx/281618162816181618168/Water-Witch-Elemental-Magic-1-by-Thea-Atkinson.pdf
    • http://owlaokopdf.myhome.cx/281648162816081678162/Bone-Witch-Elemental-Magic-3-by-Thea-Atkinson.pdf
    • http://owlaokopdf.myhome.cx/681688166816081608163/The-Broken-Witch-The-Coven-Elemental-Magic-4-by-Chandelle-LaVaun.pdf
    • http://owlaokopdf.myhome.cx/381638168816881618165/Elemental-Magic-Moon-6-5-Rai-Kirah-0-5-by-Sharon-Shinn.pdf
    • http://owlaokopdf.myhome.cx/381668160816981638169/Island-of-Glass-The-Age-of-Magic-The-Age-of-Magic-The-Glassmakers-Book-1-by-Ruth-Nestvold.pdf
    • http://owlaokopdf.myhome.cx/281638167816581658160/Earth-Logic-Elemental-Logic-Book-2-Elemental-Logic-Saga-by-Laurie-J-Marks.pdf
    • http://owlaokopdf.myhome.cx/6816281688164/Spirit-Witch-The-Lazy-Girl-s-Guide-To-Magic-3-by-Helen-Harper.pdf
    • http://owlaokopdf.myhome.cx/381628168816881658162/Sparkle-Witch-The-Lazy-Girl-s-Guide-to-Magic-3-5-by-Helen-Harper.pdf
    • http://owlaokopdf.myhome.cx/781688160816081668165/Witch-Crafting-A-Spiritual-Guide-to-Making-Magic-by-Phyllis-Curott.pdf
    • http://owlaokopdf.myhome.cx/481698168816681608162/Book-of-Earth-Diadem-Worlds-of-Magic-5-by-John-Peel.pdf
    • http://owlaokopdf.myhome.cx/1816181648166816681628160/Little-Box-of-Movie-Star-Magic-With-Movie-Star-Magic-Book-and-Glitter-Stickers-and-Vanity-Mirror-and-Makeup-and-Jewlery-and-Pictu-by-Nicci-Talbot.pdf
    • http://owlaokopdf.myhome.cx/381628165816581678162/Storm-Callers-Age-Of-Magic---A-Kurtherian-Gambit-Series-Storms-Of-Magic-2-by-P-T-Hylton.pdf
    • http://owlaokopdf.myhome.cx/481638163816681638168/Storm-Breakers-Age-Of-Magic---A-Kurtherian-Gambit-Series-Storms-Of-Magic-3-by-P-T-Hylton.pdf
    • http://owlaokopdf.myhome.cx/381628168816181688160/Steampunk-Magic-Working-Magic-Aboard-the-Airship-by-Gypsey-Elaine-Teague.pdf
    • http://owlaokopdf.myhome.cx/281678167816481618165/Gold-Magic-Terror-in-Mind-The-Magic-Series-by-John-Booth.pdf
    • http://owlaokopdf.myhome.cx/181658168816281618168/Reawakening-Age-Of-Magic---A-Kurtherian-Gambit-Series-The-Rise-of-Magic-2-by-C-M-Raymond.pdf
    • http://owlaokopdf.myhome.cx/581638167816581638161/GURPS-Grimoire-Tech-Magic-Gate-Magic-and-Hundreds-of-New-Spells-for-All-Colleges-by-Daniel-U-Thibault.pdf
    • http://owlaokopdf.myhome.cx/181618162816881698165/The-Best-Kind-of-Magic-Windy-City-Magic-1-by-Crystal-Cestari.pdf