Malicious PDF — malware analysis report

Static analysis result for SHA-256 436532b7dd7d8601…

MALICIOUS

PDF

18.5 KB Created: 2020-03-15 18:59:46 +00:00 Authoring application: mPDF 5.7
MD5: 973ca63c25e24ae1920be10df2c20611 SHA-1: 3545814fd3db5a9bc40b58963fdef6475538b62d SHA-256: 436532b7dd7d8601a20fada3ca1e304ffff673ef2ae30cb9e648ea80541d936b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with 23 external links, all pointing to PDFs hosted on the domain 'lwoscmobook.myhome.cx'. This heuristic strongly suggests a malicious intent to redirect users to potentially harmful content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9754

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/452475244524652445246/Blood-Hostages-Planescape-Blood-Wars-1-by-J-Robert-King.pdf
    • http://lwoscmobook.myhome.cx/352455243524752435246/Blood-Slave-Vampire-Wars-1-by-C-R-Guiliano.pdf
    • http://lwoscmobook.myhome.cx/252405246524352445240/Broken-Promise---Blood-Drops-Blood-Stone-1-2-by-Tracy-Cooper-Posey.pdf
    • http://lwoscmobook.myhome.cx/45241524852435242/Blood-Sins-Bishop-Special-Crimes-Unit-11-Blood-2-by-Kay-Hooper.pdf
    • http://lwoscmobook.myhome.cx/152455242524352415244/Blood-Ties-Bishop-Special-Crimes-Unit-12-Blood-3-by-Kay-Hooper.pdf
    • http://lwoscmobook.myhome.cx/452405247524752445240/Hotter-Blood-More-Tales-of-Erotic-Horror-Hot-Blood-2-by-Jeff-Gelb.pdf
    • http://lwoscmobook.myhome.cx/15241524852495245/First-Blood-Laws-of-the-Blood-5-5-Vegas-Vampires-5-Vampire-Babylon-3-5-The-Guardians-3-5-by-Susan-Sizemore.pdf
    • http://lwoscmobook.myhome.cx/352405240524452405244/Beneath-Blood-and-Bone-Thicker-Than-Blood-2-by-Madeline-Sheehan.pdf
    • http://lwoscmobook.myhome.cx/452405244524352465242/Blood-Rush-A-Tale-of-the-Blood-Breed-2-by-Jenika-Snow.pdf
    • http://lwoscmobook.myhome.cx/152455249524652415241/Blood-Forever-Blood-Coven-Vampire-8-by-Mari-Mancusi.pdf
    • http://lwoscmobook.myhome.cx/352455246524752495240/Blood-Will-Have-Blood-Michael-Spraggue-Mystery-1-by-Linda-Barnes.pdf
    • http://lwoscmobook.myhome.cx/252405246524352435248/Blood-Unleashed-Blood-Stone-3-by-Tracy-Cooper-Posey.pdf
    • http://lwoscmobook.myhome.cx/152405247524652465241/King-by-Right-of-Blood-and-Might-by-Anna-L-Walls.pdf
    • http://lwoscmobook.myhome.cx/252455241524352455248/Blood-Secrets-A-Forensic-Expert-Reveals-How-Blood-Spatter-Tells-the-Crime-Scene-s-Story-by-Rod-Englert.pdf
    • http://lwoscmobook.myhome.cx/85244524652495242/Edge-of-Destiny-Guild-Wars-2-by-J-Robert-King.pdf
    • http://lwoscmobook.myhome.cx/452455244524052485244/Half-Blood-Princess-Blood-Claim--Resurrection-Stone--Shadowed-Memories--Dark-Soul-by-Magen-McMinimy.pdf
    • http://lwoscmobook.myhome.cx/252405247524852415240/Blood-Eternal-Awakened-by-Blood-3-by-Marie-Treanor.pdf
    • http://lwoscmobook.myhome.cx/152495242524352445240/Blood-of-a-Werewolf-Blood-Series-1-by-T-Lynne-Tolles.pdf
    • http://lwoscmobook.myhome.cx/152435241524852495245/Blood-Red-The-Complete-First-Season-Blood-Red-1-by-Vivian-Wolkoff.pdf
    • http://lwoscmobook.myhome.cx/1524152455245524452485247/Bad-Blood-Leopard-Bad-Blood-Shifters-3-by-Anastasia-Wilde.pdf