Malicious PDF — malware analysis report

Static analysis result for SHA-256 383b2a4ac7823f2f…

MALICIOUS

PDF

24.4 KB Created: 2020-03-18 22:32:09 +00:00 Authoring application: mPDF 5.7
MD5: d1f647134b2ef1f8f1d15a58ec342a52 SHA-1: ba3e953f8b038d4003e451e5af1bf7ae7175c44f SHA-256: 383b2a4ac7823f2f946c39a5ba9152d152a629ea2d36121836816414fc83a06f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. The document body was unreadable, preventing a more specific analysis of its content or intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9727

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/1524052465247524752435242/Handwriting-Literacy-An-Understanding-of-Handwriting-and-the-Alphabet-That-Is-New-Enlightening-and-Encouraging-by-Angeline-Welk.pdf
    • http://lwoscmobook.myhome.cx/752465245524952475249/Computer-Recognition-and-Human-Production-of-Handwriting-by-R-Plamondon.pdf
    • http://lwoscmobook.myhome.cx/1524052465247524752435245/The-Silent-Self-by-Angeline-Welk.pdf
    • http://lwoscmobook.myhome.cx/1524052465247524752435241/The-Revelation-A-Positive-Perspective-by-Angeline-Welk.pdf
    • http://lwoscmobook.myhome.cx/1524052485247524952495246/Greek-Writing-from-Knossos-to-Homer-A-Linguistic-Interpretation-of-the-Origin-of-the-Greek-Alphabet-and-the-Continuity-of-Ancient-Greek-Literacy-by-Roger-D-Woodard.pdf
    • http://lwoscmobook.myhome.cx/1524052465247524752415249/Lawrence-Welk-146-Success-Facts---Everything-you-need-to-know-about-Lawrence-Welk-by-Stephanie-Stokes.pdf
    • http://lwoscmobook.myhome.cx/352465248524952475247/Enlightening-Delilah-The-School-for-Manners-3-by-Marion-Chesney.pdf
    • http://lwoscmobook.myhome.cx/252465240524952405242/Alphabet-Soup-Alphabet-Soup-1-Russian-Bear-2-by-C-B-Conwy.pdf
    • http://lwoscmobook.myhome.cx/352415245524952445244/Through-a-Dog-s-Eyes-Understanding-Our-Dogs-by-Understanding-How-They-See-the-World-by-Jennifer-Arnold.pdf
    • http://lwoscmobook.myhome.cx/452405242524552445245/Enlightening-the-World-Encyclop-die-The-Book-That-Changed-the-Course-of-History-by-Philipp-Blom.pdf
    • http://lwoscmobook.myhome.cx/1524052435248524752485243/Enlightening-the-World-The-Creation-of-the-Statue-of-Liberty-by-Yasmin-Sabina-Khan.pdf
    • http://lwoscmobook.myhome.cx/752475243524852445243/Understanding-Shingles-The-Understanding-Series-by-Fernando-Cr-tte.pdf
    • http://lwoscmobook.myhome.cx/452485243524252435241/Reaching-for-Celestial-Heights-Uplifting-Encouraging-and-Success-Poems-Including-Some-Written-for-Mom-and-Dad---Poems-of-Inspiration-for-Everyday-Living-by-Eddie-Johnson.pdf
    • http://lwoscmobook.myhome.cx/252435247524252465244/All-in-My-Head-An-Epic-Quest-to-Cure-an-Unrelenting-Totally-Unreasonable-and-Only-Slightly-Enlightening-Headache-by-Paula-Kamen.pdf
    • http://lwoscmobook.myhome.cx/152485249524852405248/Truthfully-Yours-by-Angeline-Hango.pdf
    • http://lwoscmobook.myhome.cx/352435247524452465241/Chosen-To-Be-His-Little-Angeline-by-Zoe-Blake.pdf
    • http://lwoscmobook.myhome.cx/252475244524052465244/A-Laird-for-All-Time-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/452405242524052475240/Someday-Angeline-by-Louis-Sachar.pdf
    • http://lwoscmobook.myhome.cx/352485245524252485243/My-Heart-s-in-the-Highlands-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/352405240524352475245/A-Time-amp-Place-for-Every-Laird-by-Angeline-Fortin.pdf
    • http://lwoscmobook.myhome.cx/1524052485247524952495246/Greek-Writi