Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b4075feb758e54d…

MALICIOUS

PDF

17.4 KB Created: 2020-03-17 03:52:47 +00:00 Authoring application: mPDF 5.7
MD5: b6861d67f36100817f054b32fa5fb33a SHA-1: df289f6ff44e0a9123743970bcb226305939cf96 SHA-256: 7b4075feb758e54da8b871199096a8a2a8e0b197b64887fdd0babcab372c148e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, a technique often used for SEO spam or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on 'owlaokopdf.myhome.cx'. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of its specific intent beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/381618160816881628164/Eternally-Forsaken-The-Eternal-Series-1-5-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/381618161816681668166/The-Eternal-Echo-The-Eternal-Series-2-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/381698163816681638163/The-Eternal-Gift-The-Eternal-Series-1-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/481698160816581688166/Lean-on-Me-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/381618163816181648160/Impending-Rayne-Adult-Edition-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/381608169816481668162/The-Dark-Hunger-A-Paranormal-Erotic-Compendium-by-Candy-Crum.pdf
    • http://owlaokopdf.myhome.cx/581648164816881648168/Brandon-Mull-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Five-Kingdom-Series-Fablehaven-Series-Beyonders-Trilogy-Candy-Shop-War-Series-Listabook-Series-Order-Book-24-by-Listabook.pdf
    • http://owlaokopdf.myhome.cx/281688169816781628165/Eternally-Eternally-Trilogy-1-by-Rae-Hachton.pdf
    • http://owlaokopdf.myhome.cx/1816181668162816881668167/Forsaken-The-Bonding-Series-3-by-Ursula-Jardine.pdf
    • http://owlaokopdf.myhome.cx/281628165816581628163/Forsaken-The-Forsaken-Saga-1-by-Sophia-Sharp.pdf
    • http://owlaokopdf.myhome.cx/48164816781698167/The-Forsaken-The-Forsaken-1-by-Lisa-M-Stasse.pdf
    • http://owlaokopdf.myhome.cx/481688166816081668169/The-Forsaken-The-Forsaken-1-by-Lisa-M-Stasse.pdf
    • http://owlaokopdf.myhome.cx/281608161816081648162/Sweet-As-Candy-CROOKED-E-RANCH-SERIES-by-S-L-Rain.pdf
    • http://owlaokopdf.myhome.cx/481698165816481608163/Riding-the-Stallion-Stetson-Series-2-by-Candy-Collins.pdf
    • http://owlaokopdf.myhome.cx/581678161816881688163/Eternal-Temptations-Tempted-Series-6-by-Janine-Infante-Bosco.pdf
    • http://owlaokopdf.myhome.cx/881608169816581618164/Manga-Publicado-En-Nakayoshi-Sailor-Moon-Cardcaptor-Sakura-Tokyo-Mew-Mew-Candy-Candy-Shugo-Chara-Jigoku-Sh-Jo-Ashita-No-Nadja-by-Books-LLC.pdf
    • http://owlaokopdf.myhome.cx/481658167816981638165/Eternal-Love-The-Immortal-Witch-Series-Immortal-Witches-1-2-amp-3-by-Maggie-Shayne.pdf
    • http://owlaokopdf.myhome.cx/481638164816181668164/Eternal-Illusion-Eternal-Island-3-by-K-S-Haigwood.pdf
    • http://owlaokopdf.myhome.cx/981638169816581638160/Eternal-Ever-After-Eternal-Vampires-Book-1-by-A-C-James.pdf
    • http://owlaokopdf.myhome.cx/381678165816181648160/Eternally-by-A-J-Myers.pdf