Malicious PDF — malware analysis report

Static analysis result for SHA-256 f303e1fd91396c2b…

MALICIOUS

PDF

16.6 KB Created: 2020-03-15 00:50:25 +00:00 Authoring application: mPDF 5.7
MD5: ddedd74d6f17c3d0f9572e76c5d8ffa9 SHA-1: 6493e8283ee6654ca20ff725f9fe2a9472292281 SHA-256: f303e1fd91396c2b62f45d70c14725c6a6c2f224f8131132d10a991dff0220b3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to book download sites, indicating a potential SEO poisoning or link farm attack. The ML classifier also flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/152445247524552425247/For-My-Lady-s-Heart-Medieval-Hearts-1-by-Laura-Kinsale.pdf
    • http://lwoscmobook.myhome.cx/352485242524852455240/For-My-Lady-s-Heart-Medieval-Hearts-1-by-Laura-Kinsale.pdf
    • http://lwoscmobook.myhome.cx/15242524652465240/My-Sweet-Folly-by-Laura-Kinsale.pdf
    • http://lwoscmobook.myhome.cx/452455248524452465242/Prince-of-Midnight-by-Laura-Kinsale.pdf
    • http://lwoscmobook.myhome.cx/15243524052475241/Seize-the-Fire-by-Laura-Kinsale.pdf
    • http://lwoscmobook.myhome.cx/452445240524052415246/Norwyck-s-Lady-Medieval-Misadventures-3-by-Margo-Maguire.pdf
    • http://lwoscmobook.myhome.cx/252405246524852455245/Racing-Hearts-Racing-Hearts-2-by-Laura-Lascarso.pdf
    • http://lwoscmobook.myhome.cx/152475243524352495245/Hearts-in-Darkness-Hearts-in-Darkness-1-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/45241524852405246/Hearts-in-Darkness-Hearts-in-Darkness-1-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/352405240524152475249/Hearts-in-Darkness-Hearts-in-Darkness-1-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/152475243524452405243/North-of-Need-Hearts-of-the-Anemoi-1-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/552485242524552495249/Lady-Outlaw-amp-Winning-the-Widow-s-Heart-Lady-Outlaw-Winning-the-Widow-s-Heart-by-Stacy-Henrie.pdf
    • http://lwoscmobook.myhome.cx/252485242524852415243/His-Leading-Lady-Hollywood-Hearts-0-5-by-Jean-C-Joachim.pdf
    • http://lwoscmobook.myhome.cx/852415241524652475243/Heath-Cliffs-amp-Wandering-Hearts-by-Laura-Barnard.pdf
    • http://lwoscmobook.myhome.cx/152475243524852415244/East-of-Ecstasy-Hearts-of-the-Anemoi-4-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/85249524252485249/South-of-Surrender-Hearts-of-the-Anemoi-3-by-Laura-Kaye.pdf
    • http://lwoscmobook.myhome.cx/352455247524352425248/Laura-Welch-Bush-First-Lady-by-Tanya-Lee-Stone.pdf
    • http://lwoscmobook.myhome.cx/452475245524252415243/When-a-Laird-Loves-a-Lady-Highlander-Vows-Entangled-Hearts-Book-1-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/452485247524852405245/Regency-Romance-Lady-Laura-and-the-Captain-by-Amelia-Fernside.pdf
    • http://lwoscmobook.myhome.cx/352415240524552445249/A-Reclusive-Heart-Hollywood-Hearts-2-by-R-L-Mathewson.pdf
    • http://lwoscmobook.myhome.cx/552485242524552495249/Lady-Outlaw-amp-Winning