Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef379553e24ffaa0…

MALICIOUS

PDF

21.1 KB Created: 2020-03-15 00:48:57 +00:00 Authoring application: mPDF 5.7
MD5: f14ade00a0aadc4bcf0483cc3fee4a37 SHA-1: 2df863880e78661301c4b4df2e8faf75c29cd122 SHA-256: ef379553e24ffaa0e79a3a70821c5f5e177e32a2f293c3c64145b1eba5c0e597
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to what appear to be book download sites. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm, suggesting the primary purpose is SEO manipulation or to distribute potentially malicious content via these links. The ML classifier strongly supports a malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/1524152425245524852485244/Lydia-s-First-Love-An-Amish-Love-Story-The-Byler-Girl-Series-Book-1-by-Emma-Joy-Widders.pdf
    • http://lwoscmobook.myhome.cx/1524152485241524952445243/Freya-The-Confession-An-Amish-Short-Story-of-Hope-and-Forgiveness-The-Freya-Series-Book-2-by-Ashley-Emma.pdf
    • http://lwoscmobook.myhome.cx/352475243524752435244/Bright-Christmas-An-Amish-Love-Story-Redeeming-Romance-Series-by-Susan-Rohrer.pdf
    • http://lwoscmobook.myhome.cx/952455246524752435249/Amish-Brotherly-Love-Corbins-Creek-Amish-Romance-Series-by-Martha-Sowell.pdf
    • http://lwoscmobook.myhome.cx/452435248524752455247/A-Love-for-Leah-The-Amish-Matchmaker-4-by-Emma-Miller.pdf
    • http://lwoscmobook.myhome.cx/352475241524552425242/Love-and-Leaving-Love-AND-Series-Book-2-by-Mary-Kate-Kopec.pdf
    • http://lwoscmobook.myhome.cx/252465242524852485246/The-LOVE-Series-The-Complete-Four-Book-Set-Love-1-4-by-M-J-Fields.pdf
    • http://lwoscmobook.myhome.cx/252415249524952445247/Escape-to-Love-Love-in-a-Hopeless-Place-2-by-Emma-Calin.pdf
    • http://lwoscmobook.myhome.cx/452415244524552495243/in-the-arms-of-my-first-love-In-the-arms-of-my-first-love-series-Book-1-by-C-Mahabeer.pdf
    • http://lwoscmobook.myhome.cx/452485245524552445249/Lab-Girl-A-story-of-Trees-Science-and-Love-by-Hope-Jahren.pdf
    • http://lwoscmobook.myhome.cx/452405248524652495247/Gladiator-Girl-An-Alternate-Reality-Action-Sports-Love-Story-by-R-H-Watson.pdf
    • http://lwoscmobook.myhome.cx/752445246524552475249/Fairfield-Amish-Romance-Katie-s-First-Social-Fairfield-Amish-Romance-Short-Story-Book-0-by-Elanor-Miller.pdf
    • http://lwoscmobook.myhome.cx/252415243524952465245/A-Mother-s-Love-short-story-1-in-Emily-series-by-Chantal-Bellehumeur.pdf
    • http://lwoscmobook.myhome.cx/252445249524752475241/Stories-of-Love-in-Black-amp-White-A-Collection-of-Short-Stories-Love-in-Black-amp-White-Series-Book-1-by-Etta-Renee.pdf
    • http://lwoscmobook.myhome.cx/152425242524552445240/Broken-Love-Story-Love-Story-3-by-Natasha-Madison.pdf
    • http://lwoscmobook.myhome.cx/252475245524652485245/Love-Etc-Talking-It-Over-Series-Book-2-by-Julian-Barnes.pdf
    • http://lwoscmobook.myhome.cx/352455245524152455244/Reflections-A-Love-Ever-After-Series-Book-3-by-Amber-Lacie.pdf
    • http://lwoscmobook.myhome.cx/1524152445240524052415247/Masters-of-Love-2-Book-Series-by-Leisa-Rayven.pdf
    • http://lwoscmobook.myhome.cx/352465249524452495240/Merry-s-Christmas-a-love-story-Redeeming-Romance-Series-by-Susan-Rohrer.pdf
    • http://lwoscmobook.myhome.cx/352455245524152455247/Remember-With-Me-Magical-Love-Series-Book-3-by-Dixie-Painter.pdf
    • http://lwoscmobook.myhome.c