Malicious PDF — malware analysis report

Static analysis result for SHA-256 bea7f7e8d9d5ee62…

MALICIOUS

PDF

17.5 KB Created: 2020-02-06 00:41:31 +00:00 Authoring application: mPDF 5.7
MD5: f9f0372009fb6cf9b77c97ecdda6148f SHA-1: 47021761e68570f9ff151d8f14e7efe209dad016 SHA-256: bea7f7e8d9d5ee62d6e8dd9e793243d39d44ade4c9cb0c87bd36c145e4faa149
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by an ML classifier and contains a large number of embedded links to external PDF files, suggesting a link farm or a distribution mechanism for further malicious content. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 23 links, predominantly using numeric slugs, pointing to the domain lwoscmobook.myhome.cx. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/1524052495243524952495241/Silver-Moon-Moon-Trilogy-Part-III-by-C-L-Bevill.pdf
    • http://lwoscmobook.myhome.cx/252485240524652495245/Silver-Moon-Silver-Moon-1-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/252485240524652495247/Black-Moon-Silver-Moon-2-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/152445246524252445245/Blood-Moon-Silver-Moon-3-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/1524052495244524152425243/Blood-Moon-Cat-Clan-2-by-C-L-Bevill.pdf
    • http://lwoscmobook.myhome.cx/152465245524752445244/Silver-Moon-by-Catherine-Lundoff.pdf
    • http://lwoscmobook.myhome.cx/252435240524052455246/Silver-Moon-by-Stephanie-Clark.pdf
    • http://lwoscmobook.myhome.cx/252455242524252425242/Beneath-a-Mountain-Moon-by-Silver-RavenWolf.pdf
    • http://lwoscmobook.myhome.cx/352405244524052405246/The-Silver-Door-Moon-amp-Sun-2-by-Holly-Lisle.pdf
    • http://lwoscmobook.myhome.cx/152435243524352455249/The-Silver-Moon-Elm-Jennifer-Scales-3-by-MaryJanice-Davidson.pdf
    • http://lwoscmobook.myhome.cx/25245524852485241/Silver-Birch-Blood-Moon-by-Ellen-Datlow.pdf
    • http://lwoscmobook.myhome.cx/952465247524952485242/Finding-Beta-Silver-Moon-Wolves-2-by-Sunny-Day.pdf
    • http://lwoscmobook.myhome.cx/452425247524352455242/Silver-Moon-The-Complete-Saga-by-Rebecca-A-Rogers.pdf
    • http://lwoscmobook.myhome.cx/752465240524752405245/Silver-Moon-The-Deja-Vu-Chronicles-2-by-Marti-Melville.pdf
    • http://lwoscmobook.myhome.cx/352425248524152425240/Mrs-Darley-s-Moon-Mysteries-A-Celebration-Of-Moon-Lore-And-Magic-by-Carole-Carlton.pdf
    • http://lwoscmobook.myhome.cx/752485245524952475248/Moon-Shot-The-Inside-Story-of-America-s-Race-to-the-Moon-by-Alan-Shepard.pdf
    • http://lwoscmobook.myhome.cx/152435245524352485245/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/952465242524152425249/Moon-O-Theism-Religion-of-a-War-and-Moon-God-Prophet-Volume-I-of-II-by-Yoel-Natan.pdf
    • http://lwoscmobook.myhome.cx/652445244524152485242/The-Adventures-of-Tintin-Vol-5-Land-of-Black-Gold-Destination-Moon-Explorers-on-the-Moon-by-Herg-.pdf
    • http://lwoscmobook.myhome.cx/352475244524852495246/Thanking-the-Moon-Celebrating-the-Mid-Autumn-Moon-Festival-by-Grace-Lin.pdf
    • http://lwoscmobook.myhome.cx/25245524852485241/Silver-Birc