Malicious PDF — malware analysis report

Static analysis result for SHA-256 c694fe86b285340e…

MALICIOUS

PDF

21.0 KB Created: 2020-02-14 23:51:03 +00:00 Authoring application: mPDF 5.7
MD5: 0959b41af3ea485c0dc4d55e83fd3f70 SHA-1: e77fb81a908023eb5d085d527a6adb87c6a60710 SHA-256: c694fe86b285340eb1db30a2d49a022dc3c86f1b4a117df0228bd937e568bce2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links predominantly point to book-related URLs on the domain 'lwoscmobook.myhome.cx'. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. The primary attack pattern appears to be a link farm designed to direct users to external resources, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252405249524552445249/Wolves-Howl-at-the-Moon-And-Other-Amazing-Facts-about-Creatures-of-the-Night-by-Cecilia-Fitzsimons.pdf
    • http://lwoscmobook.myhome.cx/452425241524652475244/Banshees-Werewolves-Vampires-and-Other-Creatures-of-the-Night-Facts-Fictions-and-First-Hand-Accounts-by-Varla-Ventura.pdf
    • http://lwoscmobook.myhome.cx/552425243524952475240/Amazing-Pictures-and-Facts-About-Punta-Cana-The-Most-Amazing-Fact-Book-for-Kids-About-Punta-Cana-by-Mina-Kelly.pdf
    • http://lwoscmobook.myhome.cx/252405249524552485248/15-Weird-Facts-You-Don-t-Know-About-Wolves-by-Grant-Lee.pdf
    • http://lwoscmobook.myhome.cx/152475245524652485245/Shadow-Creatures-The-Sherwood-Wolves-3-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152485244524552405242/Howl-at-the-Moon-The-Others-12-by-Christine-Warren.pdf
    • http://lwoscmobook.myhome.cx/1524152415249524352405246/Science-Secrets-Amazing-Scientific-Facts-and-Feats-by-Dan-Nevins.pdf
    • http://lwoscmobook.myhome.cx/552405249524452415240/Amazing-Facts-About-Australian-Native-Plants-by-Cathy-Hope.pdf
    • http://lwoscmobook.myhome.cx/152445248524352425249/Blood-Moon-Howl-2-by-Jody-Morse.pdf
    • http://lwoscmobook.myhome.cx/152465246524452455243/The-Arab-World-Thought-of-It-Inventions-Innovations-and-Amazing-Facts-by-Saima-Hussain.pdf
    • http://lwoscmobook.myhome.cx/152415242524352425246/The-Magical-Worlds-of-Lord-of-the-Rings-The-Amazing-Myths-Legends-and-Facts-Behind-the-Masterpiece-by-David-Colbert.pdf
    • http://lwoscmobook.myhome.cx/252455245524552425246/Midnight-Howl-Howl-and-Prowl-1-by-Kate-Steele.pdf
    • http://lwoscmobook.myhome.cx/152485243524452465242/Creatures-of-the-Night-by-Neil-Gaiman.pdf
    • http://lwoscmobook.myhome.cx/652455247524752455242/Nocturne-Creatures-of-the-Night-by-Traer-Scott.pdf
    • http://lwoscmobook.myhome.cx/452455249524952485245/A-Wicked-Night-Creatures-of-Darkness-2-by-Kiersten-Fay.pdf
    • http://lwoscmobook.myhome.cx/1524152405242524852445244/Saving-Jenna-Night-Creatures-1-by-Violet-Summers.pdf
    • http://lwoscmobook.myhome.cx/852455244524152405247/It-s-Always-Windy-on-Trash-Night-And-Other-Facts-of-Life-by-H-W-RARDIN.pdf
    • http://lwoscmobook.myhome.cx/252485240524552495244/Long-Night-Moon-Seasons-of-the-Moon-3-by-S-M-Reine.pdf
    • http://lwoscmobook.myhome.cx/652405243524152475241/Howl-And-Growl-Wolf-And-Cat-Shifter-Paranormal-Romance-Howl-And-Growl-Series-Book-1-by-Cloe-Cullen.pdf
    • http://lwoscmobook.myhome.cx/95245524252415244/Reign-of-the-Night-Creatures-The-Everafter-Chronicles-1-by-Casey-Sean-Harmon.pdf