Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bd6bd973bebf9eb…

MALICIOUS

PDF

18.1 KB Created: 2020-02-15 23:42:05 +00:00 Authoring application: mPDF 5.7
MD5: 8e02204cfc4c16bdc232586339921311 SHA-1: 48e543b717dec83e16444fba810e8de5a6877830 SHA-256: 0bd6bd973bebf9ebcd78319ce96434baa7e1131a1555578c849819bb40af8aee
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. The primary goal appears to be directing users to a domain hosting numerous documents, likely for SEO manipulation or to host malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252495245524852475245/Irish-Moon-Moon-Magick-1-by-Amber-Scott.pdf
    • http://lwoscmobook.myhome.cx/252405247524052485247/Amber-Moon-Prides-of-the-Moon-1-1NS-by-Ann-Mayburn.pdf
    • http://lwoscmobook.myhome.cx/452495242524552485243/Moon-Curse-Shifting-Magick-Trilogy-1-by-Lia-Davis.pdf
    • http://lwoscmobook.myhome.cx/1524052455241524852425247/Simple-Wiccan-Magick-Full-Moon-Spells-amp-Rituals-by-Holly-Zurich.pdf
    • http://lwoscmobook.myhome.cx/65247524252485243/Captive-Irish-Moon-by-Sandi-Layne.pdf
    • http://lwoscmobook.myhome.cx/352485241524052405249/Samhain-s-Kiss-Blood-Moon-and-Sun-2-by-Amber-Kell.pdf
    • http://lwoscmobook.myhome.cx/352485248524952405241/Amber-Eyes-Children-of-the-Blood-Moon-2-by-S-D-Grimm.pdf
    • http://lwoscmobook.myhome.cx/85243524252435246/Tears-of-the-Moon-Gallaghers-of-Ardmore-Irish-Trilogy-2-by-Nora-Roberts.pdf
    • http://lwoscmobook.myhome.cx/752485245524952475248/Moon-Shot-The-Inside-Story-of-America-s-Race-to-the-Moon-by-Alan-Shepard.pdf
    • http://lwoscmobook.myhome.cx/352425248524152425240/Mrs-Darley-s-Moon-Mysteries-A-Celebration-Of-Moon-Lore-And-Magic-by-Carole-Carlton.pdf
    • http://lwoscmobook.myhome.cx/952465242524152425249/Moon-O-Theism-Religion-of-a-War-and-Moon-God-Prophet-Volume-I-of-II-by-Yoel-Natan.pdf
    • http://lwoscmobook.myhome.cx/152435245524352485245/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/652445244524152485242/The-Adventures-of-Tintin-Vol-5-Land-of-Black-Gold-Destination-Moon-Explorers-on-the-Moon-by-Herg-.pdf
    • http://lwoscmobook.myhome.cx/452455241524152475247/Harvest-Moon-Blue-Moon-Lake-2-by-Sharon-Struth.pdf
    • http://lwoscmobook.myhome.cx/55249524952455249/Haunted-Moon-Otherworld-Sisters-of-the-Moon-13-by-Yasmine-Galenorn.pdf
    • http://lwoscmobook.myhome.cx/152435245524452435243/Moon-of-the-Terrible-Seasons-of-the-Moon-Cain-Chronicles-3-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/852475242524652455242/Full-Moon-Feral-Moon-Compound-2-by-Jackie-Nacht.pdf
    • http://lwoscmobook.myhome.cx/2524852435248/The-Moon-in-the-Palace-Empress-of-Bright-Moon-1-by-Weina-Dai-Randel.pdf
    • http://lwoscmobook.myhome.cx/352475244524852495246/Thanking-the-Moon-Celebrating-the-Mid-Autumn-Moon-Festival-by-Grace-Lin.pdf
    • http://lwoscmobook.myhome.cx/352495242524152435245/Moon-Bayou-Samantha-Moon-Case-Files-1-by-J-R-Rain.pdf