Malicious PDF — malware analysis report

Static analysis result for SHA-256 ceb94f8cfdc49a73…

MALICIOUS

PDF

17.8 KB Created: 2020-03-18 22:56:45 +00:00 Authoring application: mPDF 5.7
MD5: 9f98c2495810e0fe37260b03dd17bd9a SHA-1: c1d48389fb56ece6ac98f80450ffd92c78d93288 SHA-256: ceb94f8cfdc49a73085bf5353caf9287e422444f6781460d934ec81e80dacd8b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. The ML classifier also strongly indicated maliciousness. The primary attack pattern appears to be a link farm designed to direct users to potentially malicious content hosted on the 'myhome.cx' domain. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/481608163816181638160/Skin-Deep-Feral-Ink-1-by-Sarah-M-kel-.pdf
    • http://owlaokopdf.myhome.cx/481648168816681678160/Skin-to-Skin-Skin-Deep-3-by-J-M-Stone.pdf
    • http://owlaokopdf.myhome.cx/281628166816681668161/Skin-Deep-by-S-W-Vaughn.pdf
    • http://owlaokopdf.myhome.cx/481618169816581688168/Cover-Up-Skin-Deep-Inc-3-by-L-A-Witt.pdf
    • http://owlaokopdf.myhome.cx/281698168816981678163/Skin-Deep-by-Trista-Jaszczak.pdf
    • http://owlaokopdf.myhome.cx/481678161816181668161/Skin-Deep-by-Neal-Litherland.pdf
    • http://owlaokopdf.myhome.cx/481608164816381658165/Inked-Fury-Feral-Ink-2-by-Sarah-M-kel-.pdf
    • http://owlaokopdf.myhome.cx/78166816681628167/Skin-Deep-I-Team-5-5-by-Pamela-Clare.pdf
    • http://owlaokopdf.myhome.cx/381628166816881668160/Bedhead-Skin-Deep-3-by-Shoshanna-Evers.pdf
    • http://owlaokopdf.myhome.cx/481658165816181668164/Skin-Deep-Legion-2-by-Brandon-Sanderson.pdf
    • http://owlaokopdf.myhome.cx/581628162816981628165/Skin-Deep-A-SkinWalker-Novel-1-A-DarkWorld-Series-by-T-G-Ayer.pdf
    • http://owlaokopdf.myhome.cx/681668164816981618169/Dope-Dealers-Reflection-Skin-Deep-by-Malika-Holland.pdf
    • http://owlaokopdf.myhome.cx/481618165816481688165/Feral-Gaze-Feral-Silence-Rock-Star-1-by-Athena-Wright.pdf
    • http://owlaokopdf.myhome.cx/281688164816681668163/Under-My-Skin-Hannah-Wolfe-3-by-Sarah-Dunant.pdf
    • http://owlaokopdf.myhome.cx/68168816081668161/Someone-Else-s-Skin-DI-Marnie-Rome-1-by-Sarah-Hilary.pdf
    • http://owlaokopdf.myhome.cx/88160816081638163/Through-Waters-Deep-Waves-of-Freedom-1-by-Sarah-Sundin.pdf
    • http://owlaokopdf.myhome.cx/481628167816381668166/Deep-in-Crimson-Return-to-Sanctuary-2-by-Sarah-Purdy-Gilman.pdf
    • http://owlaokopdf.myhome.cx/381678169816481658162/The-Young-Skin-Diet-Science-Based-Recipes-and-Treatments-to-Reveal-Your-Best-Skin-Ever-by-Michelle-Lee.pdf
    • http://owlaokopdf.myhome.cx/58162816481688161/The-Feral-Sentence-part-3-The-Feral-Sentence-3-by-G-C-Julien.pdf
    • http://owlaokopdf.myhome.cx/881668162816181698167/Acne-Simple-Proven-Solution-To-Acne-Free-Skin-How-To-Cure-Acne-For-Good-And-Achieve-Lasting-Acne-Freedom-Acne-Cure-Acne-No-More-Acne-Diet-Clear-Skin-Free-Skin-Get-Rid-Of-Acne-Acne-Treatment-by-Donna-Flinn.pdf