Malicious PDF — malware analysis report

Static analysis result for SHA-256 b48c32082867e8ad…

MALICIOUS

PDF

20.3 KB Created: 2020-02-06 00:44:33 +00:00 Authoring application: mPDF 5.7
MD5: b74d4c18b9ba4e50b7f92284489cd455 SHA-1: d56902318bd4e340630ae7a827fed3b5c0c7b542 SHA-256: b48c32082867e8ad94372cce6a3c1c3cd42ea0fc5301a4a650cdd0c02f4bb663
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external resources. The ML classifier also strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on 'owlaokopdf.myhome.cx', likely for SEO manipulation or to serve further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/381638166816981678162/Dante-s-Inferno-the-Divine-Comedy-Volume-1-Hell-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/781608165816081668162/The-Divine-Comedy-of-Dante-Alighieri-Volume-1-Inferno-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/781628163816181678163/The-Divine-Comedy-Inferno-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/681608169816581678162/The-Divine-Comedy-The-Inferno-Purgatorio-and-Paradiso-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/581678168816081628165/The-Divine-Comedy-Of-Dante-Alighieri-Italian-Text-With-Translation-And-Comment-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/881648167816381608162/Inferno-Canto-I-a-triple-rhyme-translation-of-the-Divine-comedy-by-Sidney-Gunn-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/681608165816881618169/The-Divina-Commedia-of-Dante-Alighieri-Consisting-of-the-Inferno--Purgatorio--And-Paradiso-Tr-Into-English-Verse-with-Preliminary-Essays-Notes-and-Illustrations-by-the-REV-Henry-Boyd-Volume-2-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/781698163816781638166/The-Divine-Comedy-The-Vision-of-Dante-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/1816081648161816981608163/Divine-Comedy-The-Vision-of-Hell-Optimized-for-ebook-Illustrated-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/781698163816781638164/Dante-s-Inferno-A-Vision-From-Hell-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/881658165816781678166/LA-DIVINA-COMMEDIA-THE-DIVINE-COMEDY-Inferno-A-Translation-into-English-in-Iambic-Pentameter-Terza-Rima-form-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/1816181608166816281618162/The-Divine-Comedy-of-Dante-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/1816081668162816881678169/Divine-Comedy-of-Dante-Alighieri-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/781618163816481688167/Divine-Comedy-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/581698161816881668163/The-Divine-Comedy-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/581608163816381608165/The-Divine-Comedy-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/38169816581608169/Paradiso-The-Divine-Comedy-3-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/68167816881668169/Dante-s-Divine-Comedy-Inferno-by-Arcturus.pdf
    • http://owlaokopdf.myhome.cx/981688169816981668160/Dante-s-Inferno-A-Lineal-and-Rhymed-Translation-by-Dante-Alighieri.pdf
    • http://owlaokopdf.myhome.cx/881608163816081638163/The-Divine-Comedy-Color-Illustrated-Formatted-for-E-Readers-by-Dante-Alighieri.pdf