Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4468c544baafbee…

MALICIOUS

PDF

22.8 KB Created: 2020-03-15 22:23:52 +00:00 Authoring application: mPDF 5.7
MD5: 99418a781f2c0375f47116415f5bdfe2 SHA-1: 03b3f6fc05013e95a5c08a77598ad6ddf3d2b703 SHA-256: b4468c544baafbee53c954401133328c3922ef1137b4f98bdf7521f755a8d742
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML classifier also strongly flagged this PDF as malicious. The embedded URLs, such as http://owlaokopdf.myhome.cx/181608161816081638165/Change-by-Design-How-Design-Thinking-Transforms-Organizations-and-Inspires-Innovation-by-Tim-Brown.pdf, are likely used to redirect users to malicious sites or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/181608161816081638165/Change-by-Design-How-Design-Thinking-Transforms-Organizations-and-Inspires-Innovation-by-Tim-Brown.pdf
    • http://owlaokopdf.myhome.cx/281638164816481658165/The-Design-Revolution-Answering-the-Toughest-Questions-about-Intelligent-Design-by-William-A-Dembski.pdf
    • http://owlaokopdf.myhome.cx/681698161816381608160/Modern-C-Design-Generic-Programming-and-Design-Patterns-Applied-by-Andrei-Alexandrescu.pdf
    • http://owlaokopdf.myhome.cx/681628169816081618165/The-Language-of-Graphic-Design-An-Illustrated-Handbook-for-Understanding-Fundamental-Design-Principles-by-Richard-Poulin.pdf
    • http://owlaokopdf.myhome.cx/1816081668165816981688164/Die-Essenz-Der-Dinge-Design-Und-Die-Kunst-Der-Reduktion-the-Essence-of-Things-Design-and-the-Art-of-Reduction-by-Alexander-Von-Vegesack.pdf
    • http://owlaokopdf.myhome.cx/581638169816781648168/Design-Guide-Rome-Design-City-by-Tonino-Paris.pdf
    • http://owlaokopdf.myhome.cx/1816181698166816881618167/The-Beetle-Keith-Seume-s-Celebration-Of-The-World-s-Favorite-Cars-by-Keith-Seume.pdf
    • http://owlaokopdf.myhome.cx/481638168816881688165/Far-Flung-Floyd-Keith-Floyd-s-Guide-To-South-East-Asian-Food-by-Keith-Floyd.pdf
    • http://owlaokopdf.myhome.cx/181638165816981698166/Mildred-Keith-Mildred-Keith-1-by-Martha-Finley.pdf
    • http://owlaokopdf.myhome.cx/881668161816181678166/Design-Thinking-Workshop-12-Komponenten-die-in-keinem-Design-Thinking-Workshop-fehlen-d-rfen-by-Pauline-Tonhauser.pdf
    • http://owlaokopdf.myhome.cx/1816081688161816381648164/Complex-Systems-Design-amp-Management-Asia-Smart-Nations-Sustaining-and-Designing-Proceedings-of-the-Second-Asia-Pacific-Conference-on-Complex-Systems-Design-amp-Management-CSD-amp-M-Asia-2016-by-Michel-Alexandre-Cardin.pdf
    • http://owlaokopdf.myhome.cx/381648160816981678162/Kept-by-Sally-Bradley.pdf
    • http://owlaokopdf.myhome.cx/481648162816781698166/Adventures-of-Sally-by-P-G-Wodehouse.pdf
    • http://owlaokopdf.myhome.cx/1816181678169816281628160/My-Place-by-Sally-Morgan.pdf
    • http://owlaokopdf.myhome.cx/381698163816881678168/The-Visitors-by-Sally-Beauman.pdf
    • http://owlaokopdf.myhome.cx/481628167816481668165/The-Visitors-A-Novel-by-Sally-Beauman.pdf
    • http://owlaokopdf.myhome.cx/481688164816181638163/Cameron-by-Sally-Henson.pdf
    • http://owlaokopdf.myhome.cx/38168816681648168/I-Coriander-by-Sally-Gardner.pdf
    • http://owlaokopdf.myhome.cx/181618166816181658169/Roadwork-by-Sally-Sutton.pdf
    • http://owlaokopdf.myhome.cx/481648164816081638169/Lousy-Magnet-by-Sally-Max.pdf
    • http://owlaokopdf.myhome.cx/681628169816081618165/The-Language-of-Graphic-Design-An-Illustrated-Handbook-for-Understanding-Fundamental-Design-Principle