Malicious PDF — malware analysis report

Static analysis result for SHA-256 00253095638778c6…

MALICIOUS

PDF

21.3 KB Created: 2020-03-15 00:51:36 +00:00 Authoring application: mPDF 5.7 First seen: 2021-07-13
MD5: f617c17c0334ddede45d6d19084c75bf SHA-1: 9dcfedddac4523e40209a77d6dd1b3b8f719d311 SHA-256: 00253095638778c68bf3c0ddccdf71b0398df4f074e862173b4b95080c940ecf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, presented as links to book downloads, which is indicative of a link farm or SEO poisoning attack. The primary goal appears to be directing users to external sites, potentially for malicious content distribution. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/552475244524252455248/The-Call-of-the-Wild---Jack-London---Original-Book---ANNOTATED-by-Jack-London.pdf In PDF document text
    • http://lwoscmobook.myhome.cx/852415247524252445248/Call-of-the-Wild-by-Jack-London-Short-Adventure-Novel-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852435241/The-Call-of-the-Wild-with-eBook-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/752455248524252415244/The-Call-of-the-Wild-Illustrated-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524152455247524252495245/The-Call-of-the-Wild-Special-Edition-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/852405249524452465248/The-Call-of-the-Wild-illustrated-Supreme-Edition-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/65246524952445246/The-Call-of-the-Wild-White-Fang-and-Other-Stories-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/752415243524352435244/The-Call-of-the-Wild-With-25-Illustrations-and-a-Free-Audio-Link-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/952415241524452465245/The-Call-of-the-Wild-Centaur-Classics-The-100-greatest-novels-of-all-time---69-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/552435241524352405245/The-Call-of-the-Wild-illustrated---first-published-in-1903-1st-Page-Classics-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/752425241524552405246/The-Call-of-the-Wild-15-Illustrations-Included-Bestselling-Classic-Fiction-Books-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/652405249524652495243/The-Call-of-the-Wild-Includes-MLA-Style-Citations-for-Scholarly-Secondary-Sources-Peer-Reviewed-Journal-Articles-and-Critical-Essays-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352425244524552475247/Novels-and-Stories-The-Call-of-the-Wild-White-Fang-The-Sea-Wolf-Klondike-and-Other-Stories-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524152455249524152415242/White-Fang-by-Jack-London-a-Novel-John-Griffith-Jack-London-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/552485248524252425240/White-Fang-By-Jack-London---Illustrated-And-Unabridged-by-Jack-London.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452405246524252405245/The-Story-Of-Wild-Goose-Jack-The-Life-And-Work-Of-Jack-Miner-by-James-M-Linton.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524152425245524552435242/The-Call-of-the-Wild-Graphic-Novels-by-Neil-Kleid.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452425249524252405244/Ports-of-Call-by-Jack-Vance.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/252425248524752435248/The-Wild-s-Call-Aspect-of-Crow-0-5-by-Jeri-Smith-Ready.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/152455245524752405244/After-London-or-Wild-England-by-Richard-Jefferies.pdfIn PDF document text