Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fda1129d9df9e3a…

MALICIOUS

PDF

17.3 KB Created: 2020-03-15 00:55:09 +00:00 Authoring application: mPDF 5.7
MD5: 0f524125540b3c565b37e0366f3be593 SHA-1: 47fa52c793b034566faa1ce25d25de58bdf2e7b7 SHA-256: 5fda1129d9df9e3aaa3d93c2d7d6bef5dac77ed51be2d559128444a929f92416
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files on the domain 'owlaokopdf.myhome.cx'. This pattern is indicative of a link farm designed to distribute malicious content or engage in SEO poisoning. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/681628161816581678161/The-Warrior-s-Queen-Border-Series-6-by-Cecelia-Mecca.pdf
    • http://owlaokopdf.myhome.cx/481678164816781698165/The-Chief-s-Maiden-Border-3-by-Cecelia-Mecca.pdf
    • http://owlaokopdf.myhome.cx/381648161816781698163/The-Thief-s-Countess-Border-1-by-Cecelia-Mecca.pdf
    • http://owlaokopdf.myhome.cx/381648161816781698167/The-Ward-s-Bride-Border-0-5-by-Cecelia-Mecca.pdf
    • http://owlaokopdf.myhome.cx/5816581638160/Queen-Fae-NYC-Mecca-3-by-Jaymin-Eve.pdf
    • http://owlaokopdf.myhome.cx/281638160816481668167/Warrior-Queen-The-Story-of-Boudica-Celtic-Queen-by-Alan-Gold.pdf
    • http://owlaokopdf.myhome.cx/481658161816781698167/Qualities-of-a-Spiritual-Warrior-Way-of-the-Warrior-Series-by-Graham-Cooke.pdf
    • http://owlaokopdf.myhome.cx/88162816681668163/The-Warrior-s-Wife-The-Warrior-Series-1-by-Denise-Domning.pdf
    • http://owlaokopdf.myhome.cx/381668167816081698160/Sorcery-amp-Cecelia-or-The-Enchanted-Chocolate-Pot-Cecelia-and-Kate-1-by-Patricia-C-Wrede.pdf
    • http://owlaokopdf.myhome.cx/281608162816381618165/Border-Lass-Border-Trilogy-II-2-by-Amanda-Scott.pdf
    • http://owlaokopdf.myhome.cx/281608162816381608162/Border-Bride-Border-Trilogy-I-1-by-Amanda-Scott.pdf
    • http://owlaokopdf.myhome.cx/281608162816181698160/Border-Storm-Border-Trilogy-I-3-by-Amanda-Scott.pdf
    • http://owlaokopdf.myhome.cx/281638161816181608168/Xena-Warrior-Princess-Queen-of-the-Amazons-by-Kerry-Milliron.pdf
    • http://owlaokopdf.myhome.cx/3816381618166/Slave-Warrior-Queen-Of-Crowns-and-Glory-1-by-Morgan-Rice.pdf
    • http://owlaokopdf.myhome.cx/281698169816281678160/Border-Bride-Border-2-by-Arnette-Lamb.pdf
    • http://owlaokopdf.myhome.cx/681668164816881628162/Malika---Warrior-Queen-Part-One-An-African-Historical-Fantasy-Graphic-Novel-by-Roye-Okupe.pdf
    • http://owlaokopdf.myhome.cx/681608166816581678163/Cecelia-Ahern-2-Book-Bestsellers-Collection-One-Hundred-Names-PS-I-Love-You-by-Cecelia-Ahern.pdf
    • http://owlaokopdf.myhome.cx/98162816181618168/The-Warrior-s-Way-Pre-Aztec-series-3-by-Zoe-Saadia.pdf
    • http://owlaokopdf.myhome.cx/98162816381618163/The-Jaguar-Warrior-Pre-Aztec-Series-2-by-Zoe-Saadia.pdf
    • http://owlaokopdf.myhome.cx/281628169816081688162/Awakening-the-Warriors-The-Darkon-Warrior-Series-1-5-by-S-E-Gilchrist.pdf