Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f8f6157b72b1bd4…

MALICIOUS

PDF

16.9 KB Created: 2020-03-15 22:20:47 +00:00 Authoring application: mPDF 5.7
MD5: f58066faa2f4a6babb19f71571b0b9a4 SHA-1: 5178666a1ff9da9e830441008e27584a5dbae47f SHA-256: 9f8f6157b72b1bd420f2f7d55c3986009a2316b7038f13b6e15da9b2aa0a46f2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'owlaokopdf.myhome.cx' domain, suggesting a link farm or SEO poisoning tactic. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/281608168816181628164/Emerald-Eyes-Emerald-Eyes-Trilogy-1-by-N-Michaels.pdf
    • http://owlaokopdf.myhome.cx/181678164816781688167/Emerald-Eyes-of-The-Sea-Emerald-Trilogy-part-1-by-Hazel-Cartwright.pdf
    • http://owlaokopdf.myhome.cx/281628163816281628165/Emerald-Eyes-by-Elaine-Waldron.pdf
    • http://owlaokopdf.myhome.cx/481618160816181618169/Emerald-Eyes-Hidden-Gems-1-by-Jackie-Williams.pdf
    • http://owlaokopdf.myhome.cx/38167816181648164/Emerald-Green-The-Ruby-Red-Trilogy-3-by-Kerstin-Gier.pdf
    • http://owlaokopdf.myhome.cx/381638167816481668167/The-Fall-of-Rain-The-Emerald-Isle-Trilogy-3-by-Renee-Vincent.pdf
    • http://owlaokopdf.myhome.cx/181678165816581688168/Emerald-Green-Precious-Stone-Trilogy-3-by-Kerstin-Gier.pdf
    • http://owlaokopdf.myhome.cx/281678162816781638167/Close-Your-Eyes-Kendra-Michaels-1-by-Iris-Johansen.pdf
    • http://owlaokopdf.myhome.cx/581608161816881678163/Luke-s-Eyes-Eyes-of-Silver-Revisited-2-by-Ellen-O-39-Connell.pdf
    • http://owlaokopdf.myhome.cx/181628165816181698165/Phantom-Eyes-Witch-Eyes-3-by-Scott-Tracey.pdf
    • http://owlaokopdf.myhome.cx/281648165816881698160/Eyes-of-Silver-Eyes-of-Gold-by-Ellen-O-39-Connell.pdf
    • http://owlaokopdf.myhome.cx/381618163816281678164/One-Eye-Two-Eyes-Three-Eyes-A-Hutzul-Tale-by-Eric-A-Kimmel.pdf
    • http://owlaokopdf.myhome.cx/181628167816081678160/Demon-Eyes-Witch-Eyes-2-by-Scott-Tracey.pdf
    • http://owlaokopdf.myhome.cx/481648163816281628169/Four-Eyes-Vol-1-Forged-in-Flames-Four-Eyes-1-by-Joe-Kelly.pdf
    • http://owlaokopdf.myhome.cx/181688168816481678163/The-Jewel-Series-Bundle-2-Emerald-Fire-amp-Topaz-Heat-The-Jewel-Trilogy-2-3-by-Hallee-Bridgeman.pdf
    • http://owlaokopdf.myhome.cx/381618165816281638162/Angel-Eyes-Forever-Trilogy-3-by-B-Alston.pdf
    • http://owlaokopdf.myhome.cx/181678162816481668166/Becoming-a-Legend-Blue-Eyes-Trilogy-2-by-B-Kristin-McMichael.pdf
    • http://owlaokopdf.myhome.cx/58166816781638169/Hooked-Clasps-amp-Eyes-A-Classification-amp-Catalogue-of-Sharp--Or-Blunt-Hooked-Clasps-amp-Miscellaneous-Objects-with-Hooks-Eyes-Loops-Rings-or-Toggles-by-Brian-Read.pdf
    • http://owlaokopdf.myhome.cx/481638165816581608165/Emerald-Butterfly-by-A-P-Nuri.pdf
    • http://owlaokopdf.myhome.cx/381628161816781658163/The-Wikomsette-by-Emerald-Lavere.pdf