Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d5462e69b61389a…

MALICIOUS

PDF

18.8 KB Created: 2020-03-19 20:26:53 +00:00 Authoring application: mPDF 5.7
MD5: 59f8b62d17f5c1e185fbdd7933f03cc6 SHA-1: fb2624657d499d73ccb523ae0713542aece19319 SHA-256: 6d5462e69b61389acf16a3c4b97944d173e421441cd9b13a66ab17cbb94b5a1f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links, such as http://owlaokopdf.myhome.cx/281638161816581698168/The-Pygmy-Dragon-Shapeshifter-Dragon-Legends-1-by-Marc-Secchia.pdf, likely lead to malicious websites or serve as a distribution point for further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281638161816581698168/The-Pygmy-Dragon-Shapeshifter-Dragon-Legends-1-by-Marc-Secchia.pdf
    • http://owlaokopdf.myhome.cx/381638163816781668168/The-Pygmy-Dragon-Shapeshifter-Dragon-Legends-1-by-Marc-Secchia.pdf
    • http://owlaokopdf.myhome.cx/281658164816281698160/Dragon-Thief-by-Marc-Secchia.pdf
    • http://owlaokopdf.myhome.cx/281658164816281678165/The-Dragon-Librarian-Scrolls-of-Fire-1-by-Marc-Secchia.pdf
    • http://owlaokopdf.myhome.cx/981688168816981648168/BBW-DRAGON-SHIFTER-ROMANCE-WOLF-SHIFTER-ROMANCE-Wife-Me-Dragon-Paranormal-Alpha-Male-Shapeshifter-Romance-Werewolf-Devil-Vampire-Shifter-Romance-Short-Stories-by-Jenny-Wildner.pdf
    • http://owlaokopdf.myhome.cx/78165816181698162/Releasing-the-Dragon-Myths-and-Legends-1-by-Stacie-Simpson.pdf
    • http://owlaokopdf.myhome.cx/181658167816381668167/Legends-Legend-of-the-White-Dragon-1-by-Melanie-Nilles.pdf
    • http://owlaokopdf.myhome.cx/481668160816781668168/Return-of-the-Dragon-Knights-Legends-of-Entraydia-1-by-Alex-D-K-Courter.pdf
    • http://owlaokopdf.myhome.cx/181678165816481618164/Lady-Dragon-Tela-Du-The-Rizkaland-Legends-2-by-Kendra-E-Ardnek.pdf
    • http://owlaokopdf.myhome.cx/381628165816081618166/The-Horse-Dreamer-by-Marc-Secchia.pdf
    • http://owlaokopdf.myhome.cx/681678168816681688162/The-Blue-Dragon-A-Claire-Agon-Dragon-Book-Claire-Agon-Dragon-1-by-Salvador-Mercer.pdf
    • http://owlaokopdf.myhome.cx/1816081688169816381648161/Hidden-Dragon-Dragon-Rising-Urban-Fantasy-Series-1-by-Trudi-Jaye.pdf
    • http://owlaokopdf.myhome.cx/1816081688169816381648168/Searching-Dragon-Dragon-Rising-Urban-Fantasy-Series-2-by-Trudi-Jaye.pdf
    • http://owlaokopdf.myhome.cx/481628167816581678165/The-Billionaire-Dragon-Shifter-s-Mate-Gray-s-Hollow-Dragon-Shifters-1-by-Zoe-Chant.pdf
    • http://owlaokopdf.myhome.cx/281698169816381648167/Dragon-Knight-s-Shield-Order-of-the-Dragon-Knights-4-by-Mary-Morgan.pdf
    • http://owlaokopdf.myhome.cx/281658164816581638169/Dragon-Black-Dragon-White-Darkest-Day-Brightest-Night-The-Dragonlords-of-Xandakar-4-by-Macy-Babineaux.pdf
    • http://owlaokopdf.myhome.cx/181648160816181608162/Elmer-and-the-Dragon-My-Father-s-Dragon-2-by-Ruth-Stiles-Gannett.pdf
    • http://owlaokopdf.myhome.cx/78169816481678165/How-to-Betray-a-Dragon-s-Hero-How-to-Train-Your-Dragon-11-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/48168816181608165/How-to-Cheat-a-Dragon-s-Curse-How-to-Train-Your-Dragon-4-by-Cressida-Cowell.pdf
    • http://owlaokopdf.myhome.cx/181688169816081628165/Dead-Sexy-Dragon-Dragon-Heat-1-by-Lolita-Lopez.pdf