Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c3094b8827cf8c7…

MALICIOUS

PDF

16.1 KB Created: 2020-03-10 10:26:13 +00:00 Authoring application: mPDF 5.7
MD5: 3efa2d3c4f6f578b5afa16d49f050df5 SHA-1: 8caee922f42963e04504b17498b04da50b0d7c22 SHA-256: 6c3094b8827cf8c7d29ebffef46678d6ca4a74bee3da9c5c0c86d4cdb136830f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file contains a large number of embedded URLs pointing to a single domain, 'owlaokopdf.myhome.cx'. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm designed to generate SEO traffic or potentially distribute malicious content. The ML classifier also flagged this PDF as malicious. The embedded URLs likely serve as the primary mechanism for the attack, directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/481608169816381618167/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/681608169816981658163/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/181608160816481618168/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/781628167816481698164/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/681658169816781698166/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/381698163816781638162/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/481698168816481648162/The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/1816081648161816981688164/The-Communist-Manifesto-eBook-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/1816081608162816081608164/Manifesto-of-the-Communist-Party-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/581668168816881648169/The-Communist-Manifesto-and-Other-Writings-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/981678169816881658163/The-Communist-Manifesto-Russian-edition-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/1816081648163816281668166/Kommunist-Manifesti-The-Communist-Manifesto-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/781668166816881628162/The-Communist-Manifesto-with-Related-Documents-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/981688165816281698165/The-Communist-Manifesto-Illustrated-All-Four-Parts-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/681628164816081678169/The-Communist-Manifesto-with-Selections-from-the-Eighteenth-Brumaire-of-Louis-Bonaparte-and-Capital-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/881628165816281668165/Karl-Marx-id-es-re-ues-sur-Karl-Marx-by-Yvon-Quiniou.pdf
    • http://owlaokopdf.myhome.cx/1816181618166816581688165/Karl-Marx-und-Friedrich-Engels-Manifest-der-Kommunistischen-Partei-Das-quot-Kommunistische-Manifest-quot-in-der-Original-Fassung-von-1848-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/581668168816881648167/The-Portable-Karl-Marx-by-Karl-Marx.pdf
    • http://owlaokopdf.myhome.cx/181618162816881698166/Karl-Marx-by-Francis-Wheen.pdf
    • http://owlaokopdf.myhome.cx/581698166816181628164/Capital-in-Manga-by-Karl-Marx.pdf