Malicious PDF — malware analysis report

Static analysis result for SHA-256 353106285d905ade…

MALICIOUS

PDF

23.4 KB Created: 2020-03-15 01:08:00 +00:00 Authoring application: mPDF 5.7
MD5: 1fdadb70c0d548ed6ad853503855bf20 SHA-1: c1bdd6c3ac8f91e032e057b44ff9bcf2c2e78551 SHA-256: 353106285d905ade8dc89341769ed16dbc6ec8ed7ee6a5e5230affe06235fdd5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on the domain lwoscmobook.myhome.cx. This suggests the document's primary purpose is to act as a link farm, likely for SEO manipulation or to distribute malicious content. The ML classifier and ClamAV detection further support its malicious nature, flagging it as Pdf.Dropper.Agent-9575370-0.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9575370-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9575370-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/152415244524852445247/Road-Tripped-Ad-Agency-1-by-Nicole-Archer.pdf
    • http://lwoscmobook.myhome.cx/552405245524152465246/Road-Tripped-A-Romantic-Comedy-Adventure-by-Nicole-Archer.pdf
    • http://lwoscmobook.myhome.cx/352455242524052485241/Sentiment-to-the-Heart-Avery-Detective-Agency-1-by-Nicole-Higginbotham-Hogue.pdf
    • http://lwoscmobook.myhome.cx/452475247524352415245/Tripped-Up-Love-The-New-Ever-After-Series-1-by-Julie-Farley.pdf
    • http://lwoscmobook.myhome.cx/252485244524952465240/How-to-Archer-The-Ultimate-Guide-to-Espionage-and-Style-and-Women-and-Also-Cocktails-Ever-Written-by-Sterling-Archer.pdf
    • http://lwoscmobook.myhome.cx/1524152425242524452485245/Tripped-Out-Blacktop-Cowboys-8-5-1001-Dark-Nights-66-by-Lorelei-James.pdf
    • http://lwoscmobook.myhome.cx/952485249524852415241/No-1-Ladies-Detective-Agency-Box-Set-The-No-1-Ladies-Detective-Agency-Tears-of-the-Giraffe-Morality-for-Beautiful-Girls-by-Alexander-McCall-Smith.pdf
    • http://lwoscmobook.myhome.cx/652435247524152445249/The-Archer-The-Archers-1-by-Martin-Archer.pdf
    • http://lwoscmobook.myhome.cx/352405242524852475241/The-No-1-Ladies-Detective-Agency-No-1-Ladies-Detective-Agency-1-by-Alexander-McCall-Smith.pdf
    • http://lwoscmobook.myhome.cx/35242524652425246/The-No-1-Ladies-Detective-Agency-No-1-Ladies-Detective-Agency-1-by-Alexander-McCall-Smith.pdf
    • http://lwoscmobook.myhome.cx/352485242524852485240/The-Archer-s-Heart-Book-Three-The-Archer-s-Heart-3-by-Astrid-Amara.pdf
    • http://lwoscmobook.myhome.cx/652435247524152495244/Matt-Archer-Bloodlines-Matt-Archer-4-by-Kendra-C-Highley.pdf
    • http://lwoscmobook.myhome.cx/752415245524452475242/Dreaming-of-Brandon-Archer-Brandon-Archer-Series-by-D-J-Manly.pdf
    • http://lwoscmobook.myhome.cx/352485242524852475248/The-Archer-s-Heart-Book-Two-The-Archer-s-Heart-2-by-Astrid-Amara.pdf
    • http://lwoscmobook.myhome.cx/152405247524352445245/In-Lane-Three-Alex-Archer-Alex-Archer-1-by-Tessa-Duder.pdf
    • http://lwoscmobook.myhome.cx/552445247524352495240/Beyond-Cellulite-Nicole-Ronsard-s-Ultimate-Strategy-to-Slim-Firm-and-Reshape-Your-Lower-Body-by-Nicole-Ronsard.pdf
    • http://lwoscmobook.myhome.cx/352475246524152465249/Two-Guys-Detective-Agency-Two-Guys-Detective-Agency-1-by-Stephanie-Bond.pdf
    • http://lwoscmobook.myhome.cx/152485244524352405240/The-Dead-Kid-Detective-Agency-The-Dead-Kid-Detective-Agency-1-by-Evan-Munday.pdf
    • http://lwoscmobook.myhome.cx/352465247524552455249/The-Narrow-Road-Stories-of-Those-Who-Walk-This-Road-Together-by-Brother-Andrew.pdf
    • http://lwoscmobook.myhome.cx/652435248524552485240/Road-Novels-1957-1960-On-the-Road-The-Dharma-Bums-The-Subterraneans-Tristessa-Lonesome-Traveler-Journal-Selections-by-Jack-Kerouac.pdf
    • http://lwoscmobook.myhome.cx/952485249524852415241/No-1