Malicious PDF — malware analysis report

Static analysis result for SHA-256 7863b26e7ac96f35…

MALICIOUS

PDF

17.7 KB Created: 2020-02-15 15:52:21 +00:00 Authoring application: mPDF 5.7 First seen: 2020-09-07
MD5: f02e7e5e16c223c9fa7599b23a76eeae SHA-1: daf8974fa5b7017088dfcaf764e9427e039a4d08 SHA-256: 7863b26e7ac96f35e47f4806131f6698b5f2fb3da6fab4a0d7f58e54c2132647
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm with 23 external PDF links, suggesting a tactic to distribute or host malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a large number of potentially malicious external PDF documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/681668169816281688165/Campus-Level-One-Audio-Cassette-Program-One-by-Cle.pdf In PDF document text
    • http://owlaokopdf.myhome.cx/681668169816381638168/Panorama-Level-3-Cassette-Program-by-Cle.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/681668169816381638162/Communication-Express-Cassette-Program-by-Cle.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/481628169816581638169/Rumpole-and-the-Judges-Elbow-Audio-Cassette-by-John-Mortimer.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816681608165/Viewpoint-Level-1-Class-Audio-CDs-4-by-Michael-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816581628160/Touchstone-Level-1A-Student-s-Book-A-with-Audio-CD-CD-ROM-by-Michael-J-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816781608161/Touchstone-Level-3-Student-s-Book-A-with-Audio-CD-CD-ROM-by-Michael-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816681698169/Touchstone-Level-1-Teacher-s-Edition-with-Assessment-Audio-CD-CD-ROM-by-Michael-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816581618164/Viewpoint-Level-1-Teacher-s-Edition-with-Assessment-Audio-CD-CD-ROM-by-Michael-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/881628169816381608166/Campus-Exposures-Nancy-Drew-On-Campus-13-by-Carolyn-Keene.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/1816181678166816581648168/Prosawerke-in-Einzelausgaben-Audio-CDs-Teil-9-Lilienthal-1801-2-Audio-CDs-by-Arno-Schmidt.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/681668169816281688166/Panorama-Level-2-with-Booklet-and-Level-2-Exercise-Workbook-by-Cle.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/381628168816881678163/The-Program-The-Program-1-by-Suzanne-Young.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/38164816081648167/The-Program-The-Program-1-by-Suzanne-Young.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/481638162816081698163/Campus-Cravings-Vol-3-Campus-Cravings-6-7-by-Carol-Lynne.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/481638162816081698164/Campus-Cravings-Vol-2-Campus-Cravings-4-5-by-Carol-Lynne.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981648169816681608164/Touchstone-Class-Audio-CDs-1-Class-Audio-CDs-L1-Pack-4-by-Michael-J-McCarthy.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981698160816281668160/Cassette-Mythos-by-Robin-James.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/981658163816081628163/Pas-de-Probl-Me-A-Complete-Course-Cassette-Set-and-Transcript-by-Madeleine-Hummler.pdfIn PDF document text
    • http://owlaokopdf.myhome.cx/881608168816181698163/Voila-An-Introduction-To-French-With-CDROM-and-Cassette-by-L-Kathy-Heilenman.pdfIn PDF document text