Malicious PDF — malware analysis report

Static analysis result for SHA-256 0940145c6868de02…

MALICIOUS

PDF

20.8 KB Created: 2020-03-15 00:49:55 +00:00 Authoring application: mPDF 5.7
MD5: 0f471d3cc19715680162f7fc7b894903 SHA-1: 1356a385705023f0619d3edcaf8fe68674b2d6a0 SHA-256: 0940145c6868de028fbdfad99265c10b130be1be434b05f61db00f480e1bc07b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links all point to a single domain, eascasas.myhome.cx, and appear to be designed to mimic book titles. This suggests a tactic to manipulate search engine results or to distribute potentially malicious content disguised as legitimate documents. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/1aa4aa3aa7aa0aa3/Dona-Flor-A-Tall-Tale-About-a-Giant-Woman-with-a-Great-Big-Heart-by-Pat-Mora.pdf
    • http://eascasas.myhome.cx/9aa9aa3aa7aa0aa8/Great-American-Short-Stories-vol-1-The-Birthmark-The-Threefold-Destiny-An-Old-Woman-s-Tale-by-Nathaniel-Hawthorne.pdf
    • http://eascasas.myhome.cx/4aa7aa0aa3aa6aa1/Underground-in-Berlin-A-Young-Woman-s-Extraordinary-Tale-of-Survival-in-the-Heart-of-Nazi-Germany-by-Marie-Jalowicz-Simon.pdf
    • http://eascasas.myhome.cx/2aa4aa0aa7aa3aa7/The-Tall-Woman-by-Wilma-Dykeman.pdf
    • http://eascasas.myhome.cx/4aa7aa2aa2aa9aa7/The-Tall-Tale-of-Tommy-Twice-by-Nathan-Leslie.pdf
    • http://eascasas.myhome.cx/5aa1aa9aa5aa1aa2/Kumak-s-Fish-A-Tall-Tale-from-the-Far-North-by-Michael-Bania.pdf
    • http://eascasas.myhome.cx/2aa8aa6aa4aa1aa2/Homo-Action-Love-Story-A-tall-tale-by-Ben-Monopoli.pdf
    • http://eascasas.myhome.cx/1aa2aa9aa0aa3aa5/Nowhere-Else-on-Earth-Standing-Tall-for-the-Great-Bear-Rainforest-by-Caitlyn-Vernon.pdf
    • http://eascasas.myhome.cx/1aa2aa4aa1aa3aa3/Stand-Tall-They-ll-Break-Your-Heart-by-Monique-Diplock.pdf
    • http://eascasas.myhome.cx/2aa1aa7aa1aa8aa7/Roping-Your-Heart-Riding-Tall-2-by-Cheyenne-McCray.pdf
    • http://eascasas.myhome.cx/1aa9aa5aa2aa3aa8/Heart-Of-Stone-Long-Tall-Texans-35-by-Diana-Palmer.pdf
    • http://eascasas.myhome.cx/7aa8aa6aa3aa0aa5/Paydunor-The-Giant-Web-The-Giant-Web-by-Brad-Allen-Deborde.pdf
    • http://eascasas.myhome.cx/4aa9aa9aa0aa5aa7/The-Tale-of-the-Little-Little-Old-Woman-by-Elsa-Beskow.pdf
    • http://eascasas.myhome.cx/4aa8aa1aa6aa1aa7/Articles-on-Books-by-Beatrix-Potter-Including-The-Tale-of-Peter-Rabbit-the-Tale-of-Samuel-Whiskers-or-the-Roly-Poly-Pudding-the-Tale-of-the-Flopsy-Bunnies-the-Tale-of-Squirrel-Nutkin-the-Tale-of-Mr-Jeremy-Fisher-by-Hephaestus-Books.pdf
    • http://eascasas.myhome.cx/6aa8aa1aa3aa0aa5/The-Selfish-Giant-Le-Geant-Egoiste-Oscar-Wilde-Bilingual-French-English-Fairy-Tale-Dual-Language-Picture-Book-by-Oscar-Wilde.pdf
    • http://eascasas.myhome.cx/7aa6aa4aa9/The-Woman-s-Hour-The-Great-Fight-to-Win-the-Vote-by-Elaine-F-Weiss.pdf
    • http://eascasas.myhome.cx/1aa2aa8aa2aa1aa3/Faery-Tale-One-Woman-s-Search-for-Enchantment-in-a-Modern-World-by-Signe-Pike.pdf
    • http://eascasas.myhome.cx/4aa9aa2aa8aa9aa1/The-Heart-of-a-Woman-by-Maya-Angelou.pdf
    • http://eascasas.myhome.cx/4aa0aa9aa1aa3/A-Woman-After-God-s-Own-Heart-by-Elizabeth-George.pdf
    • http://eascasas.myhome.cx/1aa0aa5aa4aa7aa8/The-Tell-Tale-Heart-by-Edgar-Allan-Poe.pdf