Malicious PDF — malware analysis report

Static analysis result for SHA-256 7eaceff3dcb648d0…

MALICIOUS

PDF

18.4 KB Created: 2020-03-18 22:37:05 +00:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: ee04d98bbfda0c2217831ba26266cfc2 SHA-1: e85a02f3ebcd55449d3ff3d198fdac619107ddd5 SHA-256: 7eaceff3dcb648d0413a513667684671542b705d94c0711c341bb494ae335672
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on a domain that appears to be part of a link farm. This technique is often used to distribute malicious content or to manipulate search engine rankings. The ML classifier also flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/852415248524552425249/Harpsichord-Pieces-Book-1-Suite-5-No-7-La-Badine-by-Fran-ois-Couperin.pdf In PDF document text
    • http://lwoscmobook.myhome.cx/652485241524852455244/Harpsichord-Pieces-Book-4-Suite-23-No-5-Les-satires-chevre-pieds-by-Fran-ois-Couperin.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/552405241524052405245/A-Suite-Life-Suite-Love-Series-Book-2-by-Sue-Gibson.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/252475242524052465247/From-the-Complaint-Desk-of-Fran-Lewis-I-Speak-the-Truth-You-need-to-Hear-It-by-Fran-Lewis.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452455246524452425247/Picking-Up-the-Pieces-Broken-Book-1-by-E-L-Green.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/652485245524752445241/Musset-On-ne-badine-pas-avec-l-amour-by-Merle.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/552495245524752405244/Into-a-Million-Pieces-Pieces-Duology-1-by-Angela-V-Cook.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/852415248524552435246/Classiques-Bordas-On-ne-badine-pas-avec-l-amour-by-Alfred-de-Musset.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452495240524952435242/Falling-to-Pieces-Pieces-1-by-Jamie-Canosa.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/652465244524052405242/Historical-Harpsichord-Technique-Developing-La-Douceur-Du-Toucher-by-Yonit-Lea-Kosovske.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/652465246524152405246/Big-Book-of-Beginner-s-Piano-Classics-83-Favorite-Pieces-in-Easy-Piano-Arrangements-with-Downloadable-MP3s-by-Bergerac.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452445249524952455244/Pieces-of-Us-Pieces-2-by-Pamela-Ann.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/45244524952425240/Broken-Pieces-Broken-Pieces-1-by-Riley-Hart.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/152465249524752445246/Pieces-of-Lies-Pieces-of-Lies-1-by-Angela-Richardson.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/452495247524052475249/Suite-Dubai-by-Callista-Fox.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/652485243524952415243/Suite-Fantasy-by-Janice-Maynard.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/1524152495240524752435248/CAIRO-SUITE-FG-by-Lucette-Lagnado.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352425246524452465242/The-Chrome-Suite-by-Sandra-Birdsell.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/352445240524252425242/The-Elephanta-Suite-by-Paul-Theroux.pdfIn PDF document text
    • http://lwoscmobook.myhome.cx/35240524252445245/The-Angry-Woman-Suite-by-Lee-Fullbright.pdfIn PDF document text