Malicious PDF — malware analysis report

Static analysis result for SHA-256 aae8965cc0455b49…

MALICIOUS

PDF

23.2 KB Created: 2020-03-15 00:50:20 +00:00 Authoring application: mPDF 5.7
MD5: d658b7c6ce459e4cf4d93c04f94644c8 SHA-1: 1341e1f38f036a014feafdd95a5ac82cdc531e2e SHA-256: aae8965cc0455b49c97d25ae4e9877b0aa7fdbef3655e8274b76a55da2b28fc1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links. These links, such as http://lwoscmobook.myhome.cx/352495240524352405249/Butterflies-And-Late-Loves-The-Further-Travels-And-Adventures-Of-A-Victorian-Lady-by-Margaret-Fountaine.pdf, are likely intended to lure users to malicious websites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/352495240524352405249/Butterflies-And-Late-Loves-The-Further-Travels-And-Adventures-Of-A-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://lwoscmobook.myhome.cx/352435248524452465248/Love-among-the-Butterflies-The-Travels-and-Adventures-of-a-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://lwoscmobook.myhome.cx/252485248524452415243/Late-Victorian-Gothic-Tales-by-Roger-Luckhurst.pdf
    • http://lwoscmobook.myhome.cx/152405240524152455247/Becoming-Modern-in-Toronto-The-Industrial-Exhibition-and-the-Shaping-of-a-Late-Victorian-Culture-by-Keith-Walden.pdf
    • http://lwoscmobook.myhome.cx/252405246524252495248/Lady-Laugherty-s-Loves-by-Laurel-Bennett.pdf
    • http://lwoscmobook.myhome.cx/252485248524352455244/The-Lady-Loves-to-Strip-by-James-Lusarde.pdf
    • http://lwoscmobook.myhome.cx/1524052495247524152445244/Please-Save-Me-Before-It-s-Too-Late-by-Lady-Lissa.pdf
    • http://lwoscmobook.myhome.cx/452425244524752415243/Tucket-s-Travels-Francis-Tucket-s-Adventures-In-The-West-1847-1849-The-Tucket-Adventures-1-5-by-Gary-Paulsen.pdf
    • http://lwoscmobook.myhome.cx/352435243524852405241/Unmentionable-The-Victorian-Lady-s-Guide-to-Sex-Marriage-and-Manners-by-Therese-Oneill.pdf
    • http://lwoscmobook.myhome.cx/95248524852435247/Unmentionable-The-Victorian-Lady-s-Guide-to-Sex-Marriage-and-Manners-by-Therese-Oneill.pdf
    • http://lwoscmobook.myhome.cx/452475245524252415243/When-a-Laird-Loves-a-Lady-Highlander-Vows-Entangled-Hearts-Book-1-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/25249524452405240/The-All-True-Travels-and-Adventures-of-Lidie-Newton-by-Jane-Smiley.pdf
    • http://lwoscmobook.myhome.cx/152415249524652495245/Butterflies-Wake-Butterflies-1-by-Arlene-Lagos.pdf
    • http://lwoscmobook.myhome.cx/452425243524752475248/A-Round-Heeled-Woman-My-Late-Life-Adventures-in-Sex-and-Romance-by-Jane-Juska.pdf
    • http://lwoscmobook.myhome.cx/452425240524652415249/A-Round-Heeled-Woman-My-Late-Life-Adventures-in-Sex-amp-Romance-by-Jane-Juska.pdf
    • http://lwoscmobook.myhome.cx/952485244524952465242/Cakewalk-Adventures-In-Sugar-With-Margaret-Braun-by-Margaret-Braun.pdf
    • http://lwoscmobook.myhome.cx/252425246524252415243/Lady-Oracle-by-Margaret-Atwood.pdf
    • http://lwoscmobook.myhome.cx/55248524552475249/Lady-s-Maid-by-Margaret-Forster.pdf
    • http://lwoscmobook.myhome.cx/152475246524952455244/The-Pirate-And-His-Lady-by-Margaret-St-George.pdf
    • http://lwoscmobook.myhome.cx/552405244524852485249/How-to-Be-a-Victorian-A-Dawn-to-Dusk-Guide-to-Victorian-Life-by-Ruth-Goodman.pdf
    • http://lwoscmobook.myhome.cx/152405240524152455247/Becoming-Modern-in-Toronto-The-Industrial-Exhibition-and-the-Shaping-of-a-Late-Victor