Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7b835fc043a3d0a…

MALICIOUS

PDF

22.0 KB Created: 2020-02-15 09:51:46 +00:00 Authoring application: mPDF 5.7
MD5: 23f74efbe9c730752b961f15de12c92e SHA-1: 25b009924ade29377d2f2eea175e3347d47905e3 SHA-256: e7b835fc043a3d0aa53004aee4fc1913b81a1ede90efe00a871c9691680c53bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, many with numeric slugs, pointing to external PDF files. This indicates a likely attempt to create a link farm for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/1816181678162816181678163/The-Little-Prince-Family-Storybook-Unabridged-Original-Text-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/1816181608162816281628168/THE-LITTLE-PRINCE-ILLUSTRATED-The-English-Edition-and-Original-French-Edition-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/1816081628167816481608164/Le-Petit-Prince-The-Little-Prince-in-French-Boxed-Edition-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/681648166816981668162/The-Picture-of-Dorian-Gray-Complete-Original-amp-Unabridged-Authoritative-Text-with-Selected-Criticism-amp-Background-Notes-by-Oscar-Wilde.pdf
    • http://owlaokopdf.myhome.cx/48163816681688168/The-Little-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/581648162816981608165/The-Little-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/481658163816081688160/The-Little-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/781618165816481698165/The-Little-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/681648166816681698161/The-Little-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/38164816581698161/The-Little-Prince-amp-Letter-to-a-Hostage-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/281658169816681608162/the-little-prince----by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/581638169816681658168/The-Pilot-and-the-Little-Prince-The-Life-of-Antoine-de-Saint-Exup-ry-by-Peter-S-s.pdf
    • http://owlaokopdf.myhome.cx/581688160816181608162/The-Little-Prince-Western-Armenian-edition-Pokrig-Ishkhane-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/981678169816681678167/Der-Kleine-Prinz-German-Edition-of-The-Little-Prince-Audio-Compact-Disc-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/481638162816781638164/A-Guide-for-Grown-ups-Essential-Wisdom-from-the-Collected-Works-of-Antoine-de-Saint-Exup-ry-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/681638169816181618162/Der-Kleine-Prinz---Il-Piccolo-Principe-Zweisprachiger-paralleler-Text---Bilingue-con-testo-a-fronte-Deutsch---Italienisch-Tedesco---Italiano-Dual-Language-Easy-Reader-57-by-Antoine-de-Saint-Exup-ry.pdf
    • http://owlaokopdf.myhome.cx/581678164816081638165/The-Old-Man-and-the-Sea-original-unabridged-Annotated-by-Ernest-Hemingway.pdf
    • http://owlaokopdf.myhome.cx/581678164816181688166/Heart-of-Darkness-Original-and-Unabridged-by-Joseph-Conrad.pdf
    • http://owlaokopdf.myhome.cx/681638166816481648167/The-Picture-of-Dorian-Gray-Annotated-Unabridged-text-and-Study-Guide-by-Oscar-Wilde.pdf
    • http://owlaokopdf.myhome.cx/88161816381628164/The-Complete-K-ma-S-tra-The-First-Unabridged-Modern-Translation-of-the-Classic-Indian-Text-by-Mallanaga-V-tsy-yana.pdf
    • http://owlaokopdf.myhome.cx/581648162816981608165/The-Little-Prince-by-Antoi