Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae5292915c88ffbf…

MALICIOUS

PDF

17.4 KB Created: 2020-03-17 04:01:41 +00:00 Authoring application: mPDF 5.7
MD5: 1f846eca06cceadd039e448248755cdd SHA-1: 5464e4418571881c39fc033c2bbafa394528e76a SHA-256: ae5292915c88ffbf9e5957f9eb32a30a8aa98c8ad0dc4247bb9da0ccf4610e15
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm, likely for SEO manipulation or to redirect users to potentially harmful content hosted on the dominant host 'owlaokopdf.myhome.cx'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/781628166816881688169/A-Liverpool-Legacy-by-Anne-Baker.pdf
    • http://owlaokopdf.myhome.cx/781628166816881648169/Goodbye-Liverpool-by-Anne-Baker.pdf
    • http://owlaokopdf.myhome.cx/581608161816281668165/Lies-Beneath-Lies-Beneath-1-by-Anne-Greenwood-Brown.pdf
    • http://owlaokopdf.myhome.cx/48163816981608164/Lies-Beneath-Lies-Beneath-1-by-Anne-Greenwood-Brown.pdf
    • http://owlaokopdf.myhome.cx/681678162816981608160/Paradise-Parade-by-Anne-Baker.pdf
    • http://owlaokopdf.myhome.cx/181648166816781648165/Merseyside-Girls-by-Anne-Baker.pdf
    • http://owlaokopdf.myhome.cx/281688160816381678167/The-Prince-of-Lies-Night-s-Masque-3-by-Anne-Lyle.pdf
    • http://owlaokopdf.myhome.cx/181618162816881608165/Lies-My-Girlfriend-Told-Me-by-Julie-Anne-Peters.pdf
    • http://owlaokopdf.myhome.cx/381658161816581618169/American-Conspiracies-Lies-Lies-and-More-Dirty-Lies-that-the-Government-Tells-Us-by-Jesse-Ventura.pdf
    • http://owlaokopdf.myhome.cx/181608161816081618160/American-Conspiracies-Lies-Lies-and-More-Dirty-Lies-that-the-Government-Tells-Us-by-Jesse-Ventura.pdf
    • http://owlaokopdf.myhome.cx/88169816881648165/Pack-of-Lies-Paranormal-Scene-Investigations-2-by-Laura-Anne-Gilman.pdf
    • http://owlaokopdf.myhome.cx/181648165816581618162/Love-Lies-amp-High-Heels-Love-Lies-and-More-Lies-1-by-Debby-Conrad.pdf
    • http://owlaokopdf.myhome.cx/58163816881608160/Confections-of-a-Closet-Master-Baker-One-Woman-s-Sweet-Journey-from-Unhappy-Hollywood-Executive-to-Contented-Country-Baker-by-Gesine-Bullock-Prado.pdf
    • http://owlaokopdf.myhome.cx/481658162816481688168/Auschwitz-Lies-Legends-Lies-And-Prejudices-On-The-Holocaust-by-Carlo-Mattogno.pdf
    • http://owlaokopdf.myhome.cx/4816881638166/Crown-of-Lies-Truth-and-Lies-Duet-1-by-Pepper-Winters.pdf
    • http://owlaokopdf.myhome.cx/181678164816881688164/Deceiving-Lies-Forgiving-Lies-2-by-Molly-McAdams.pdf
    • http://owlaokopdf.myhome.cx/681688161816281648165/Sex-Lies-amp-Bourbon-Sex-and-Lies-Book-5-by-Kris-Calvert.pdf
    • http://owlaokopdf.myhome.cx/381608169816781668161/Beneath-the-Lies-Living-With-Lies-1-by-Riann-C-Miller.pdf
    • http://owlaokopdf.myhome.cx/78160816081608163/Who-on-Earth-is-Tom-Baker-by-Tom-Baker.pdf
    • http://owlaokopdf.myhome.cx/681608166816681668163/Au-Revoir-Liverpool-by-Maureen-Lee.pdf