Malicious PDF — malware analysis report

Static analysis result for SHA-256 d207956d771c25c0…

MALICIOUS

PDF

21.8 KB Created: 2020-03-18 22:49:14 +00:00 Authoring application: mPDF 5.7
MD5: c9d2cf58af723ba6a2a872fb409bf676 SHA-1: 2be714416c91f2b615c35f44e9261d015b5af39e SHA-256: d207956d771c25c0aaa0b6f7b92e2f03d142a26a300d6d73d9e10b8fe4feadd5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the domain 'owlaokopdf.myhome.cx'. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/881648169816081698160/Frankenstein-Mary-Shelley-The-Modern-Prometheus-Frankenstein-s-Monster-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681668163816581638164/The-Essential-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681648168816581608163/The-Story-of-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618160816081618163/Frankenstein-Galvanised-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581678161816681638163/Frankenstein-o-el-moderno-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581648162816481608160/Frankenstein-or-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781618161816381688164/Frankenstein-narrated-by-Dan-Stevens-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688161816181628166/Frankenstein-Or-the-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681628164816281608162/Frankenstein-o-el-nuevo-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-Original-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681678165816881608164/Frankenstein-Dracula-Dr-Jekyll-And-Mr-Hyde-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581668167816881638167/Frankenstein---playscript-adapted-by-Philip-Pullman-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881638169816681618161/Robert-Andrew-Parker-s-Illustrated-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781658169816781648163/Frankenstein-or-The-Modern-Prometheus-The-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681658161816381658165/Frankenstein-Or-the-Modern-Prometheus-1823-Revolution-amp-Romanticism-1789-1834-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881608167816381648161/Frankenstein-Gothic-Classic---The-Uncensored-1818-Edition-Science-Fiction-Classic-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618164816881688168/The-Life-and-Letters-of-Mary-Wollstonecraft-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658161816281668160/The-Mortal-Immortal-The-Complete-Supernatural-Short-Fiction-of-Mary-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658160816481658167/Mary-and-Maria-by-Mary-Wollstonecraft-amp-Matilda-by-Mary-Shelley-by-Mary-Wollstonecraft.pdf
    • http://owlaokopdf.myhome.cx/781638161816981648160/Frankenstein-or-The-Modern-Prometheus-Companion-Includes-Study-Guide-Complete-Unabridged-Book-Historical-Context-Biography-Character-Index-and-Unabridged-Book-Annotated-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-O