Malicious PDF — malware analysis report

Static analysis result for SHA-256 77692386513260d2…

MALICIOUS

PDF

16.5 KB Created: 2020-03-18 21:26:14 +00:00 Authoring application: mPDF 5.7
MD5: fff546392bb575771b330f4a2a776c39 SHA-1: ddfb3530c030fa4d9e7f2e731043fd9963825fa0 SHA-256: 77692386513260d21b6a4d68089bbe199e28ff78e08b8650fff855dbc668282e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm designed to direct users to external PDF documents. This behavior is indicative of SEO poisoning or a similar traffic-driving scheme. The ML classifier also flagged the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/581648160816281698165/Perseverance-Entretien-Avec-Serge-Toubiana-by-Serge-Daney.pdf
    • http://owlaokopdf.myhome.cx/581648160816081608168/Tropical-Warning-An-Original-Serge-Storms-Story-and-Other-Debris-Serge-Storms-series-by-Tim-Dorsey.pdf
    • http://owlaokopdf.myhome.cx/581648160816081678168/David-Cronenberg-Interviews-with-Serge-Gr-nberg-by-Serge-Gr-nberg.pdf
    • http://owlaokopdf.myhome.cx/881608160816281628169/Me-and-The-Cretin-by-Katie-Wright.pdf
    • http://owlaokopdf.myhome.cx/88163816581608164/The-Genius-Wars-Genius-3-by-Catherine-Jinks.pdf
    • http://owlaokopdf.myhome.cx/881608160816481628169/THE-SMILING-TREE-A-cretin-in-Crete-A-MAN-AND-HIS-CHAPBOOKS-Book-1-by-David-Mar.pdf
    • http://owlaokopdf.myhome.cx/281648161816481618163/Girl-Genius-Omnibus-Volume-1-Agatha-Awakens-Girl-Genius-1-3-by-Phil-Foglio.pdf
    • http://owlaokopdf.myhome.cx/881608160816381688162/Diary-of-a-Imbecile-The-Insane-Rablings-of-a-Noted-Modern-Day-Cretin-by-Keith-Pepperell.pdf
    • http://owlaokopdf.myhome.cx/881608160816381618167/Alternative-Systems-For-Case-Mix-Classification-In-Health-Care-Financing-by-Shan-Cretin.pdf
    • http://owlaokopdf.myhome.cx/7816181618166/Idiot-Genius-Willa-Snap-and-the-Clockwerk-Boy-Idiot-Genius-1-by-Richard-Due.pdf
    • http://owlaokopdf.myhome.cx/581658168816381658166/UV-by-Serge-Joncour.pdf
    • http://owlaokopdf.myhome.cx/781688168816281698169/Les-prisonniers-by-Serge-Dalens.pdf
    • http://owlaokopdf.myhome.cx/481628163816881638167/New-York-by-Serge-Ramelli.pdf
    • http://owlaokopdf.myhome.cx/581648160816081618162/Memoirs-of-a-Revolutionary-by-Victor-Serge.pdf
    • http://owlaokopdf.myhome.cx/581688165816581678163/The-New-Criticism-In-France-by-Serge-Doubrovsky.pdf
    • http://owlaokopdf.myhome.cx/681608160816181608168/Les-Alchimistes-Au-Moyen-Age-by-Serge-Hutin.pdf
    • http://owlaokopdf.myhome.cx/1816181638161816681668163/Fighter-Pilot-by-Mac-39-Serge-39-Tucker.pdf
    • http://owlaokopdf.myhome.cx/581658163816381658169/Le-Suaire-carlate-by-Serge-Brussolo.pdf
    • http://owlaokopdf.myhome.cx/781608169816181698167/L-enfance-retrouvee-Une-vie-en-psychanalyse-by-Serge-Lebovici.pdf
    • http://owlaokopdf.myhome.cx/681678161816481688166/Poup-es-sanglantes-Douarnenez-by-Serge-Le-Gall.pdf