Malicious PDF — malware analysis report

Static analysis result for SHA-256 6ec0b5c0c406e2f5…

MALICIOUS

PDF

17.0 KB Created: 2020-03-18 22:32:14 +00:00 Authoring application: mPDF 5.7 First seen: 2021-10-16
MD5: b8b2ed0ee19419ca52ea47b0d5f11de1 SHA-1: 7ff639e9a91c233a4fa0588e4ffbb7d0af265d5f SHA-256: 6ec0b5c0c406e2f53655d686f9359b054a52b10fba327b06db04e41ae6ee5a88
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, each pointing to a PDF file that appears to be a book. This technique is often used to drive traffic to malicious sites or to host further malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/552405240524552495249/The-Cardturner-by-Louis-Sachar.pdf In PDF document text
    • http://lwoscmobook.myhome.cx/1524452495244/Fuzzy-Mud-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352425246524152475241/Holes-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852445247/Holes-A-Play-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852445241/Flying-Birthday-Cake-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352455241524252415240/Is-He-a-Girl-Marvin-Redpost-3-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/752435243524252455249/Sideways-Stories-from-Wayside-School-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852455242/Activities-Based-on-Holes-by-Louis-Sachar-by-Liz-Broad.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/85247524052455242/Wayside-School-Gets-A-Little-Stranger-By-Louis-Sachar-A-Novel-Study-by-Ron-Leduc.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852445246/Holes-by-Louis-Sachar-A-Novel-Teaching-Pack-by-Margaret-Whisnant.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524152455240524652445240/Schlamm-oder-Die-Katastrophe-von-Heath-Cliff-Roman-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524852455241/There-s-a-Boy-in-the-Girl-s-Bathroom-by-Louis-Sachar-Teacher-Guide-by-Anne-Troy.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052445241524752425249/Stanley-Yelnats-Survival-Guide-to-Camp-Green-Lake-Holes-1-5-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/252425246524352495249/Someday-Girl-Someday-1-by-Melanie-Shawn.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352425245524952465246/Holes-Holes-1-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/15240524352425240/Someday-Someday-Maybe-by-Lauren-Graham.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452485246524052405243/More-Sideways-Arithmetic-from-Wayside-School-Wayside-School-2-6-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/35245524152405244/Sideways-Stories-from-Wayside-School-Wayside-School-1-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352465246524652415241/Wayside-School-Gets-a-Little-Stranger-Wayside-School-3-by-Louis-Sachar.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524052465247524752435245/The-Silent-Self-by-Angeline-Welk.pdfIn PDF document text