Malicious PDF — malware analysis report

Static analysis result for SHA-256 91ca569761d0b8e2…

MALICIOUS

PDF

14.5 KB Created: 2020-03-19 03:35:39 +00:00 Authoring application: mPDF 5.7
MD5: 29bae649853c8f93de982e1f08996d69 SHA-1: 1c3adbd3068ef6859abb166440fb635d781867ba SHA-256: 91ca569761d0b8e2791afe4a7d185a559991d137a3e90949a0bf5b004b4572ed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely part of a scheme to drive traffic to potentially malicious or phishing websites. The document body was unreadable, but the presence of numerous external links strongly suggests a social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/481698160816781698161/In-the-Name-of-Love-Rest-in-Peace-by-Nitya-Prakash.pdf
    • http://owlaokopdf.myhome.cx/481668163816281618161/Massage-by-Bi-Feiyu.pdf
    • http://owlaokopdf.myhome.cx/481648169816381678160/Heated-Massage-by-K-C-Bloom.pdf
    • http://owlaokopdf.myhome.cx/181628169816981638165/Chocolate-Lovers-Sweet-Stories-About-Love-Friendship-and-Inappropriate-Behavior-Chocolate-Lovers-1-3-5-by-Tara-Sivec.pdf
    • http://owlaokopdf.myhome.cx/281698160816681688161/The-Gin-Lovers-The-Gin-Lovers-1-by-Jamie-Brenner.pdf
    • http://owlaokopdf.myhome.cx/581688169816181628165/Hate-2-Lovers-2-Lovers-2-by-K-Webster.pdf
    • http://owlaokopdf.myhome.cx/681618165816181688169/Himeros-Massage-by-Matthew-Scrivens.pdf
    • http://owlaokopdf.myhome.cx/98168816681628161/The-Medium-is-the-Massage-by-Marshall-McLuhan.pdf
    • http://owlaokopdf.myhome.cx/1816081628166816481678167/Kiss-of-Fay-by-Maria-M-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816581608160/Through-My-Veins-Second-Story-4-by-J-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/681698169816681608160/The-Grave-Marker-by-Don-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/681668167816481628160/Gard-by-Dominique-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/88165816181688168/Tibetan-Relaxation-Kum-Nye-Massage-and-Movement-by-Tarthang-Tulku.pdf
    • http://owlaokopdf.myhome.cx/181628164816781678166/Massage-Therapy-The-Sunny-Centre-2-by-Greg-Webber.pdf
    • http://owlaokopdf.myhome.cx/181608168816081678163/Night-Wave-by-Todd-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816481688168/The-Billionaire-s-Offer-by-Lila-Lacroix.pdf
    • http://owlaokopdf.myhome.cx/181678167816081638167/Pirate-s-Mistress-by-Marianne-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181678168816581618167/Eternal-Embrace-by-Marianne-LaCroix.pdf
    • http://owlaokopdf.myhome.cx/1816181668165816381688165/The-Relaxed-Rabbit-Massage-for-Your-Pet-Bunny-by-Chandra-Moira-Beal.pdf
    • http://owlaokopdf.myhome.cx/981698160816381648167/Das-Geheimnis-der-Feentochter-I-II-eBundle-by-Maria-M-Lacroix.pdf