Malicious PDF — malware analysis report

Static analysis result for SHA-256 6722e64394a97c91…

MALICIOUS

PDF

19.2 KB Created: 2020-02-14 23:51:01 +00:00 Authoring application: mPDF 5.7
MD5: 8190e1d552cae2d731fbcfa6e30d15fe SHA-1: 1033bf37cedb797ec6bf343aab97d2c289223d87 SHA-256: 6722e64394a97c912de44a0144826b07fc7fbdbad78e0e61bcb56a38bf2349ab
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links pointing to external PDF files on the domain 'lwoscmobook.myhome.cx'. This behavior is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. The ML classifier also flagged this document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252435244524952415244/Blood-on-the-Moon-The-Federal-Witch-7-by-T-S-Paul.pdf
    • http://lwoscmobook.myhome.cx/252435244524852495248/Witness-Enchantment-The-Federal-Witch-4-by-T-S-Paul.pdf
    • http://lwoscmobook.myhome.cx/252435249524652415247/Crest-of-the-Blood-Moon-Blood-Moon-3-by-Robin-P-Waldrop.pdf
    • http://lwoscmobook.myhome.cx/252425243524552475248/Blood-Moon-Blood-Moon-1-by-Dawn-Thompson.pdf
    • http://lwoscmobook.myhome.cx/152445246524852435242/Blood-Moon-The-Blood-Moon-Legacy-1-by-A-D-Ryan.pdf
    • http://lwoscmobook.myhome.cx/152485243524852475249/Under-Witch-Moon-Moon-Shadows-1-by-Maria-E-Schneider.pdf
    • http://lwoscmobook.myhome.cx/652405247524552425244/The-Letters-of-Fabius-in-1788-on-the-Federal-Constitution-Edited-by-Paul-L-Ford-by-John-Dickinson.pdf
    • http://lwoscmobook.myhome.cx/152435245524352485245/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/152445246524252445245/Blood-Moon-Silver-Moon-3-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/452425241524852405242/Scarlet-Moon-Children-of-the-Blood-Moon-1-by-S-D-Grimm.pdf
    • http://lwoscmobook.myhome.cx/552415245524852495244/Blood-Moon-The-Blood-Chronicles-2-by-Tamela-Quijas.pdf
    • http://lwoscmobook.myhome.cx/1524152445246524652435241/Federal-Motion-Picture-Commission-Hearings-Before-the-Committee-on-Education-House-of-Representatives-Sixty-Fourth-Congress-First-Session-on-H-R-456-a-Bill-to-Create-a-New-Division-of-the-Bureau-of-Education-to-Be-Known-as-the-Federal-Motion-Pictu-by-Forgotten-Books.pdf
    • http://lwoscmobook.myhome.cx/152495246524152405240/Under-Witch-Aura-Moon-Shadows-2-by-Maria-E-Schneider.pdf
    • http://lwoscmobook.myhome.cx/252465249524152485242/The-Witch-s-Tongue-Charlie-Moon-9-by-James-D-Doss.pdf
    • http://lwoscmobook.myhome.cx/252425241524652485245/Bound-by-Blood-The-Garner-Witch-1-by-P-A-Lupton.pdf
    • http://lwoscmobook.myhome.cx/152475242524552465240/Blood-Witch-Sweep-3-by-Cate-Tiernan.pdf
    • http://lwoscmobook.myhome.cx/752495245524452455245/Elf-Blood-Witch-Fairy-14-by-Bonnie-Lamer.pdf
    • http://lwoscmobook.myhome.cx/55242524952435245/The-Blood-Maker-and-the-Witch-s-Curse-by-Jaromy-Henry.pdf
    • http://lwoscmobook.myhome.cx/252495247524052455249/True-of-Blood-Witch-Fairy-1-by-Bonnie-Lamer.pdf
    • http://lwoscmobook.myhome.cx/152445247524752415249/Blood-Vengeance-The-Draven-Witch-2-by-Zoey-Sweete.pdf