Malicious PDF — malware analysis report

Static analysis result for SHA-256 97fbec7860d5dacc…

MALICIOUS

PDF

16.8 KB Created: 2020-03-10 11:40:14 +00:00 Authoring application: mPDF 5.7
MD5: c9bc85bec68ff0eaac68e7762153d35e SHA-1: e1d3ba3bcd58dd8d5366b77d754a6176b0a46e82 SHA-256: 97fbec7860d5daccc359d84a0a72c457f33926ef0384f0ca7b4c9921f4e79686
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on the domain lwoscmobook.myhome.cx, likely as a lure or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252425244524652415247/True-Luck-True-Love-1-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/152475241524652495244/Leo-Tops-Aries-Signs-of-Love-1-5-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/152475241524852415249/Scorpio-Hates-Virgo-Signs-of-Love-2-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/15241524352495245/Tremaine-s-True-Love-True-Gentlemen-1-by-Grace-Burrowes.pdf
    • http://lwoscmobook.myhome.cx/452485243524952455247/DJ-Dangerfield-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/252425243524552475241/-Un-Masked-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/152475246524652485245/-In-visible-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/252455246524352475248/Taboo-For-You-Friends-to-Lovers-1-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/152495245524152465248/The-F-Words-Enemies-to-Lovers-4-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/252425243524652405242/William-Enemies-to-Lovers-3-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/252485240524652455243/Rainbows-Rowan-and-True-True-Romance-Ally-s-World-11-by-Karen-McCombie.pdf
    • http://lwoscmobook.myhome.cx/552405241524152445247/Rainbows-Rowan-and-True-True-Romance-Ally-s-World-11-by-Karen-McCombie.pdf
    • http://lwoscmobook.myhome.cx/152475240524952445249/True-Choices-True-3-by-Willow-Madison.pdf
    • http://lwoscmobook.myhome.cx/352445244524452425249/Will-s-True-Wish-True-Gentlemen-3-by-Grace-Burrowes.pdf
    • http://lwoscmobook.myhome.cx/252415242524052465249/True-Control-True-4-2-by-Willow-Madison.pdf
    • http://lwoscmobook.myhome.cx/252455245524052495247/True-Beginnings-True-2-by-Willow-Madison.pdf
    • http://lwoscmobook.myhome.cx/252475240524652485244/True-Devotion-True-2-by-Liora-Blake.pdf
    • http://lwoscmobook.myhome.cx/852415241524452435246/Love-by-Deception-A-harrowing-true-story-of-love-and-betrayal-by-K-C-Barnard.pdf
    • http://lwoscmobook.myhome.cx/152475242524052405240/I-Love-You-Phillip-Morris-A-True-Story-of-Life-Love-amp-Prison-Breaks-by-Steve-McVicker.pdf
    • http://lwoscmobook.myhome.cx/452495248524452435244/True-Love-Caitlin-Love-Trilogy-3-by-Francine-Pascal.pdf
    • http://lwoscmoboo