Malicious PDF — malware analysis report

Static analysis result for SHA-256 dbb27eb1b1095211…

MALICIOUS

PDF

17.7 KB Created: 2020-03-15 01:07:43 +00:00 Authoring application: mPDF 5.7
MD5: 9d80212245fb5a39a447a10072a3be34 SHA-1: bf56b72873c85ddbf048724b942e5e9af882242b SHA-256: dbb27eb1b1095211cf127798c4cd6f96b31267f520e2dcf0d86da6c88013f1cc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of numerous external links suggests a redirection or SEO manipulation scheme, potentially leading to malicious content or phishing pages. The primary attack pattern involves leveraging the PDF structure to distribute a high volume of external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/1524052475245524752455242/Driving-Me-to-You-London-Loves-1-by-Julie-Farrell.pdf
    • http://lwoscmobook.myhome.cx/152415242524852485241/She-Loves-You-She-Loves-You-Not-by-Julie-Anne-Peters.pdf
    • http://lwoscmobook.myhome.cx/452475245524252415243/When-a-Laird-Loves-a-Lady-Highlander-Vows-Entangled-Hearts-Book-1-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/352415243524752435246/He-Loves-Me-He-Loves-You-Not-by-Lauren-Hammond.pdf
    • http://lwoscmobook.myhome.cx/1524152455249524152415242/White-Fang-by-Jack-London-a-Novel-John-Griffith-Jack-London-by-Jack-London.pdf
    • http://lwoscmobook.myhome.cx/352425243524552415241/London-Calling-A-Countercultural-History-of-London-Since-1945-by-Barry-Miles.pdf
    • http://lwoscmobook.myhome.cx/252445246524552485244/London-s-Sinful-Secret-The-Bawdy-History-and-Very-Public-Passions-of-London-s-Georgian-Age-by-Dan-Cruickshank.pdf
    • http://lwoscmobook.myhome.cx/152475249524252495249/London-Pride--The-10-000-Lions-of-London-by-Valerie-Colin-Russ.pdf
    • http://lwoscmobook.myhome.cx/852465248524652485241/Die-Schatten-von-London-In-Aeternum-Shades-of-London-3-by-Maureen-Johnson.pdf
    • http://lwoscmobook.myhome.cx/152445242524652425241/Happy-New-Year-Julie-1974-American-Girls-Julie-3-by-Megan-McDonald.pdf
    • http://lwoscmobook.myhome.cx/152445242524652475246/Julie-Tells-Her-Story-American-Girls-Julie-2-by-Megan-McDonald.pdf
    • http://lwoscmobook.myhome.cx/152445242524552475240/Julie-and-the-Eagles-American-Girls-Julie-4-by-Megan-McDonald.pdf
    • http://lwoscmobook.myhome.cx/352455240524052495249/Julie-and-Julia-My-Year-of-Cooking-Dangerously-by-Julie-Powell.pdf
    • http://lwoscmobook.myhome.cx/552405241524552475244/Julie-and-Julia-My-Year-of-Cooking-Dangerously-by-Julie-Powell.pdf
    • http://lwoscmobook.myhome.cx/452465242524852485248/Chase-the-Ace-London-Lads-1-by-Clare-London.pdf
    • http://lwoscmobook.myhome.cx/452415244524852405246/Driving-into-the-Sun-by-Dev-Bentham.pdf
    • http://lwoscmobook.myhome.cx/452445244524852435242/Driving-Blind-by-Ray-Bradbury.pdf
    • http://lwoscmobook.myhome.cx/95246524752465244/Driving-in-LA-by-Brenda-Bakke.pdf
    • http://lwoscmobook.myhome.cx/25246524252425247/Driving-Blind-by-Ray-Bradbury.pdf
    • http://lwoscmobook.myhome.cx/452435248524552495240/Driving-Her-Crazy-by-Amy-Andrews.pdf
    • http://lwoscmobook.myhome.cx/252445246524552485244/London-s-Sinful-Secret-The-Bawdy-History-and-Very-Public-Passions-of-London-s-Georgian-Age-by-Dan-Cru