Malicious PDF — malware analysis report

Static analysis result for SHA-256 2954b7358d227605…

MALICIOUS

PDF

21.8 KB Created: 2020-03-18 11:29:14 +00:00 Authoring application: mPDF 5.7
MD5: c78941520e772af3a806b63df4b7d669 SHA-1: dece732cf149c235a4d4079249055cccb5396a89 SHA-256: 2954b7358d227605e0470703e25db1fbd8aeb2ea6227030b8b06010e3419c6be
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be the distribution of a large number of links, likely for SEO manipulation or to serve as a distribution point for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/652465244524052405242/Historical-Harpsichord-Technique-Developing-La-Douceur-Du-Toucher-by-Yonit-Lea-Kosovske.pdf
    • http://lwoscmobook.myhome.cx/652465243524852475240/Tout-en-douceur-by-Kim-Bose.pdf
    • http://lwoscmobook.myhome.cx/552425246524552415244/Children-s-Book-The-Dragon-Who-Couldn-t-Breathe-Fire-by-Yonit-Werber.pdf
    • http://lwoscmobook.myhome.cx/852415248524552425249/Harpsichord-Pieces-Book-1-Suite-5-No-7-La-Badine-by-Fran-ois-Couperin.pdf
    • http://lwoscmobook.myhome.cx/1524152495240524752445241/Le-Toucher-Du-Rayon-Proust-Vautrin-Et-Antinous-Essai-by-Lucette-Finas.pdf
    • http://lwoscmobook.myhome.cx/652485241524852455244/Harpsichord-Pieces-Book-4-Suite-23-No-5-Les-satires-chevre-pieds-by-Fran-ois-Couperin.pdf
    • http://lwoscmobook.myhome.cx/552475244524852495240/Pieces-de-Luth-En-Musique-Avec-Des-Regles-Pour-Les-Toucher-Parfaitement-Sur-Le-Luth-Et-Sur-Le-Clavessin-Parigi-1680-by-Perrine.pdf
    • http://lwoscmobook.myhome.cx/652455246524352435241/Current-Progress-in-Historical-Linguistics-Proceedings-of-the-Second-International-Conference-on-Historical-Linguistics-Tucson-Arizona-12-16-Janua-by-William-M-Christie.pdf
    • http://lwoscmobook.myhome.cx/952475241524552475246/The-Vineland-Historical-Magazine-Volumes-1-3-by-Vineland-Historical-and-Antiquarian-Soci.pdf
    • http://lwoscmobook.myhome.cx/1524052455240524152455247/Historical-Studies-On-Folk-And-Traditional-Music-Ictm-Study-Group-On-Historical-Sources-Of-Folk-Music-Conference-Report-Copenhagen-24-28-April-1995-by-Doris-Stockmann.pdf
    • http://lwoscmobook.myhome.cx/652465241524552455249/Act-4-Art-Technology-Technique-by-John-Gange.pdf
    • http://lwoscmobook.myhome.cx/1524152455246524852415248/Propaganda-Technique-in-World-War-I-by-Harold-D-Lasswell.pdf
    • http://lwoscmobook.myhome.cx/352445249524552435243/Decorating-Technique-and-Style-by-Barty-Phillips.pdf
    • http://lwoscmobook.myhome.cx/952455244524252455242/Freytag-s-Technique-of-The-Drama-by-Elias-J-MacEwan.pdf
    • http://lwoscmobook.myhome.cx/652455244524452455245/Technique-of-Psychoanalytic-Therapy-by-Sandor-Lorand.pdf
    • http://lwoscmobook.myhome.cx/652415240524252405244/Technique-of-the-Coup-de-Banque-by-Abdalqadir-as-Sufi.pdf
    • http://lwoscmobook.myhome.cx/152455249524052415243/Learning-to-Pray-in-the-Age-of-Technique-by-Gon-alo-M-Tavares.pdf
    • http://lwoscmobook.myhome.cx/852445240524752405246/Isherwood-s-Fiction-The-Self-and-Technique-by-Lisa-M-Schwerdt.pdf
    • http://lwoscmobook.myhome.cx/552495245524352425243/History-Philosophy-and-Technique-by-David-Chow.pdf
    • http://lwoscmobook.myhome.cx/1524052455242524952465246/The-Technique-of-Film-Editing-by-Karel-Reisz.pdf