Malicious PDF — malware analysis report

Static analysis result for SHA-256 19d2bd79a531a911…

MALICIOUS

PDF

22.1 KB Created: 2020-02-05 06:42:21 +00:00 Authoring application: mPDF 5.7
MD5: ef183ec09263a5193512a617a2f98275 SHA-1: 3d7a2d1364f2825d148af525c401527ace22d388 SHA-256: 19d2bd79a531a911fc61436c03337375bc0d93c36c7c18611441c703bf66281f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links all point to the same domain, lwoscmobook.myhome.cx, suggesting a link farm designed to redirect users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/45247524152435249/The-Bat-by-Mary-Roberts-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/252475248524352475249/Bab-A-Sub-Deb-by-Mary-Roberts-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/452405242524052485241/The-Red-Lamp-by-Mary-Roberts-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/252465244524052485246/The-Circular-Staircase-by-Mary-Roberts-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/252465241524752465241/The-Circular-Staircase-by-Mary-Roberts-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/752485249524752475245/Tartes-Gouters-Entremets-by-Stephan-Glacier-by-St-phane-Glacier.pdf
    • http://lwoscmobook.myhome.cx/1524152465242524952465240/Jurassic-Park-Michael-Crichton-List-of-Jurassic-Park-Characters-the-Lost-World-Jurassic-Park-Jurassic-Park-III-Biological-Issue-by-Source-Wikipedia.pdf
    • http://lwoscmobook.myhome.cx/952425247524652485241/What-a-Day-in-the-Park-by-Mary-Elizabeth-Salzmann.pdf
    • http://lwoscmobook.myhome.cx/652485249524152415240/Memory-Luba-Art-and-the-Making-of-History-by-Mary-Nooter-Roberts.pdf
    • http://lwoscmobook.myhome.cx/452485249524652465247/Intimate-Outsiders-The-Harem-in-Ottoman-and-Orientalist-Art-and-Travel-Literature-by-Mary-Roberts.pdf
    • http://lwoscmobook.myhome.cx/952455244524152425244/Armin-T-Wegner-e-gli-Armeni-in-Anatolia-1915-Immagini-e-Testimonianze---Armin-T-Wegner-and-the-Armenians-in-Anatolia-1915-Images-and-Testimonies-by-Armin-T-Wegner.pdf
    • http://lwoscmobook.myhome.cx/1524152485249524752445242/The-Song-of-the-Lark-1915-by-Willa-Cather-The-Song-of-the-Lark-Is-the-Third-Novel-by-American-Author-Willa-Cather-Written-in-1915-It-Is-Generally-Considered-to-Be-the-Second-Novel-in-Cather-s-Prairie-Trilogy-Following-O-Pioneers-1913-and-Pre-by-Willa-Cather.pdf
    • http://lwoscmobook.myhome.cx/75242524852445244/Estes-Park-and-Rocky-Mountain-National-Park-Then-amp-Now-by-James-H-Pickering.pdf
    • http://lwoscmobook.myhome.cx/352405242524352415241/Under-the-Glacier-by-Halld-r-Kiljan-Laxness.pdf
    • http://lwoscmobook.myhome.cx/152445241524552465249/Eliza-and-the-Dragonfly-by-Susie-Caldwell-Rinehart.pdf
    • http://lwoscmobook.myhome.cx/852435244524952485249/Crf-9-Electronic-Tech-HS-amp-T-Int-08-Blue-by-Holt-Rinehart-and-Winston-Inc-.pdf
    • http://lwoscmobook.myhome.cx/152485244524552435243/The-Snow-Leopard-s-Home-Glacier-Leopards-3-by-Zoe-Chant.pdf
    • http://lwoscmobook.myhome.cx/952445246524752405248/Love-Finds-You-in-Glacier-Bay-Alaska-by-Tricia-Goyer.pdf
    • http://lwoscmobook.myhome.cx/152455247524852465242/The-Wild-Inside-Glacier-Mystery-1-by-Christine-Carbo.pdf
    • http://lwoscmobook.myhome.cx/852455247524752435248/The-Illustrated-Guide-to-Glacier-Travel-and-Crevasse-Rescue-by-Andy-Tyson.pdf
    • http://lwoscmobook.myhome.cx/652485249524152415240/Memory-Luba-Art-and-the-Making-of-Hist