Malicious PDF — malware analysis report

Static analysis result for SHA-256 94f95cfaf18dbf02…

MALICIOUS

PDF

19.6 KB Created: 2020-03-15 22:25:18 +00:00 Authoring application: mPDF 5.7
MD5: b15dce4fc6550f26f82e4e71e772f026 SHA-1: ee22649650e9cd21544e808d1a8356aeb2091183 SHA-256: 94f95cfaf18dbf023cbd5d25f36c19f1aabc29f0471fb8122e866cc1bbbb190a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. These URLs are likely intended to redirect users to external sites, potentially for content delivery or phishing purposes. The dominant host for these links is owlaokopdf.myhome.cx.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/681608165816181618162/Sexy-Love-Sexy-4-by-Dani-Lovell.pdf
    • http://owlaokopdf.myhome.cx/681608164816981678166/Sexy-Hart-Sexy-3-by-Dani-Lovell.pdf
    • http://owlaokopdf.myhome.cx/881688163816081678160/sexy-M-dchen-mit-sexy-Arsch-18-Erotische-Fotos-Erwachsene-Nacktheit-by-Cupido.pdf
    • http://owlaokopdf.myhome.cx/481638163816981678165/The-Sexy-Boss-Sedition-The-Sexy-Series-by-T-R-Bertrand.pdf
    • http://owlaokopdf.myhome.cx/381608168816981688162/The-Sexy-amp-The-Undead-Sexy-Witches-1-by-Charity-Parkerson.pdf
    • http://owlaokopdf.myhome.cx/1816081668162816681688165/Young-Sexy-Babe---Book-454-Young-cute-chicks-sexy-photos-by-Johnny-Gunn.pdf
    • http://owlaokopdf.myhome.cx/1816181618164816181678163/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-wife-who-s-crazy-for-BBC-and-will-do-anything-for-a-sexy-black-African-dominant-to-be-her-stud-by-Ronnie-Kinski.pdf
    • http://owlaokopdf.myhome.cx/1816081658165816981688168/-Lesbian-Sexy-Photo-Of-Hot-Girls-Full-Nudity-Erotic-Books-Hot-Sexy-Pictures-New-Adult-Paranormal-Romance-With-Sex-Real-Sex-Pics-Photography-Of-Women-Nude-Photography-Milf-Pictures-Books-by-Marica-Sexotits.pdf
    • http://owlaokopdf.myhome.cx/681618162816581678161/Manhattan-Sexy-Love-by-Cristina-Prada.pdf
    • http://owlaokopdf.myhome.cx/181648165816381698168/Seven-Sexy-Sins-Love-in-Reverse-1-by-Serenity-Woods.pdf
    • http://owlaokopdf.myhome.cx/381658164816781628165/Crazy-Sexy-Love-Dirty-Dicks-1-by-K-L-Grayson.pdf
    • http://owlaokopdf.myhome.cx/181688169816081648160/Must-Love-Dragons-Immortally-Sexy-2-by-Stephanie-Rowe.pdf
    • http://owlaokopdf.myhome.cx/281688163816081618165/Crazy-Horny-Lady-Crazy-Sexy-Love-Stories-Book-1-by-Lindsay-Valentine.pdf
    • http://owlaokopdf.myhome.cx/18169816881648167/B-Boy-Blues-A-Seriously-Sexy-Fiercely-Funny-Black-on-Black-Love-Story-by-James-Earl-Hardy.pdf
    • http://owlaokopdf.myhome.cx/181648168816681638169/Simply-Sexy-by-Linda-Francis-Lee.pdf
    • http://owlaokopdf.myhome.cx/981678162816781688160/Sexy-Dolls-456-Only-Teens-by-Nuart.pdf
    • http://owlaokopdf.myhome.cx/281628162816881698164/You-Don-t-Know-Jack-Sexy-in-NYC-2-by-Erin-McCarthy.pdf
    • http://owlaokopdf.myhome.cx/481698163816881628160/Sexy-Rock-Me-4-by-Arabella-Quinn.pdf
    • http://owlaokopdf.myhome.cx/5816781628165/Sexy-Stranger-by-Kendall-Ryan.pdf
    • http://owlaokopdf.myhome.cx/181638161816081668163/Bloody-Sexy-by-Carmilla-Voiez.pdf
    • http://owlaokopdf.myhome.cx/181608165