Malicious PDF — malware analysis report

Static analysis result for SHA-256 7856c80ce7f3825b…

MALICIOUS

PDF

16.7 KB Created: 2020-03-18 21:43:18 +00:00 Authoring application: mPDF 5.7
MD5: 414a906d3291b6efe897b58015dfa9e9 SHA-1: 4d72910ef132acbb8497d1e307a625ceba892a7c SHA-256: 7856c80ce7f3825b77f6395dc0c7a5db55802172a031e8cece09d0c1cdbd7571
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files hosted on the domain 'owlaokopdf.myhome.cx'. This heuristic firing indicates a link farm, suggesting the document is designed to drive traffic to these external resources. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/981608164816381608162/In-the-Spirit-of-Hegel-by-Robert-C-Solomon.pdf
    • http://owlaokopdf.myhome.cx/981608164816381688167/Routledge-Philosophy-Guidebook-to-Hegel-and-the-Phenomenology-of-Spirit-by-Robert-Stern.pdf
    • http://owlaokopdf.myhome.cx/981608164816481698167/Hegel-s-Phenomenology-of-Spirit-An-Introduction-by-Larry-Krasnoff.pdf
    • http://owlaokopdf.myhome.cx/1816181668166816581638166/Phenomenology-of-Spirit-by-Georg-Wilhelm-Friedrich-Hegel.pdf
    • http://owlaokopdf.myhome.cx/88167816881638161/Preface-to-the-Phenomenology-of-Spirit-by-Georg-Wilhelm-Friedrich-Hegel.pdf
    • http://owlaokopdf.myhome.cx/681648168816281608162/Hegel-Passe-Hegel-a-Venir-by-Claude-Amey.pdf
    • http://owlaokopdf.myhome.cx/981608164816381608161/The-Hegel-Reader-by-Georg-Wilhelm-Friedrich-Hegel.pdf
    • http://owlaokopdf.myhome.cx/681608169816481628161/What-Nietzsche-Really-Said-by-Robert-C-Solomon.pdf
    • http://owlaokopdf.myhome.cx/281698168816681678161/The-Savage-Tales-of-Solomon-Kane-by-Robert-E-Howard.pdf
    • http://owlaokopdf.myhome.cx/78163816981698160/The-Savage-Tales-of-Solomon-Kane-by-Robert-E-Howard.pdf
    • http://owlaokopdf.myhome.cx/481688168816081678167/Solomon-Kane-The-Complete-Tales-by-Robert-E-Howard.pdf
    • http://owlaokopdf.myhome.cx/281658164816081698169/The-Solomon-Key-The-Solomon-Key-2-by-Shawn-Hopkins.pdf
    • http://owlaokopdf.myhome.cx/18168816181698168/India-Unveiled-Spirit-Tradition-People-by-Robert-Arnett.pdf
    • http://owlaokopdf.myhome.cx/881658160816581618162/A-Little-Ramble-In-the-Spirit-of-Robert-Walser-by-Robert-Walser.pdf
    • http://owlaokopdf.myhome.cx/181638160816081658165/The-Black-Canoe-Bill-Reid-and-the-Spirit-of-Haida-Gwaii-by-Robert-Bringhurst.pdf
    • http://owlaokopdf.myhome.cx/881658164816881608163/The-Spirit-of-Kaizen-Creating-Lasting-Excellence-One-Small-Step-at-a-Time-by-Robert-Maurer.pdf
    • http://owlaokopdf.myhome.cx/181698166816981618160/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://owlaokopdf.myhome.cx/1816181658169816281658164/Walking-in-the-Spirit-A-Study-of-Paul-s-Teaching-on-the-Spirit-and-Ethics-in-Galatians-by-KWESI-OTOO.pdf
    • http://owlaokopdf.myhome.cx/181698164816381608168/School-Spirit-Day-Spirit-Week-3-by-Alshia-Moyez.pdf
    • http://owlaokopdf.myhome.cx/481618161816481608165/Dark-Spirit-Spirit-Wild-2-by-Kate-Douglas.pdf