Malicious PDF — malware analysis report

Static analysis result for SHA-256 16c02d8972c42584…

MALICIOUS

PDF

19.1 KB Created: 2020-03-14 15:04:43 +00:00 Authoring application: mPDF 5.7
MD5: 030dca3df5857c23a30ebc64350f6cb6 SHA-1: 15b1ca378253f28ad8681e39e229fac7ed2bb827 SHA-256: 16c02d8972c42584077d30c69828f88cbe2b5b8c754f3d529c3ab4af976b7000
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded links, identified as a PDF link farm. These links point to external PDF files hosted on the domain 'easckaolp.myhome.cx', suggesting a tactic to distribute or link to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/3843846847847840/The-Incal-The-Epic-Journey-The-Incal-4-6-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844845848847846/The-Incal-The-Epic-Conspiracy-The-Incal-1-3-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844846841840847/The-Incal-Vol-2-The-Incal-3-4-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844846840840842/The-Incal-Vol-3-The-Incal-5-6-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/3840845848844844/Before-the-Incal-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/8845845845849/Der-Incal-Bd-4-In-h-chsten-H-hen-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844845848841849/The-Spiritual-Journey-of-Alejandro-Jodorowsky-The-Creator-of-El-Topo-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/2843849848846/Deconstructing-the-Incal-by-Christophe-Quillien.pdf
    • http://easckaolp.myhome.cx/1843843841849842/Son-of-the-Gun-Sinner---Volume-1-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/4844843842843848/The-Metabarons-Poet-and-Killer-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/3843844845844849/The-Metabarons-1-Othon-amp-Honorata-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844845848846849/The-Metabarons-4-Aghora-amp-the-Last-Metabaron-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844846841841842/Raising-Cain-Bouncer-1-2-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844846841840842/The-Technopriests-Book-Two-Rebellion-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/3840845848845840/The-Technopriests-Oversized-Deluxe-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844845848842841/Anarchy-and-Alchemy-The-Films-of-Alejandro-Jodorowsky-by-Ben-Cobb.pdf
    • http://easckaolp.myhome.cx/5844846841840841/The-White-Lama-Book-1-The-First-Step-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/5844846840849847/The-Technopriests-Techno-Pre-School-Techno-Priests-by-Alejandro-Jodorowsky.pdf
    • http://easckaolp.myhome.cx/6846841842840844/Articles-on-French-Comics-Writers-Including-Ren-Goscinny-Enki-Bilal-Jacques-Tardi-Alejandro-Jodorowsky-Sylvain-Chomet-Joann-Sfar-Jacques-Martin-Comics-Fran-OIS-Bourgeon-Emmanuel-Larcenet-David-Beauchard-Lewis-Trondheim-by-Hephaestus-Books.pdf
    • http://easckaolp.myhome.cx/3846848842840844/Last-Flag-Down-The-Epic-Journey-of-the-Last-Confederate-Warship-by-John-Baldwin.pdf