Malicious PDF — malware analysis report

Static analysis result for SHA-256 18b0508fcc939463…

MALICIOUS

PDF

15.6 KB Created: 2020-03-18 21:15:04 +00:00 Authoring application: mPDF 5.7
MD5: b55ca67541c957e453fdec94f77a62ac SHA-1: f5cf9beee4e97278bdddbec083c26b63fe9d52f0 SHA-256: 18b0508fcc93946335bde164077658fb4666857115e0d0f7e2c006149b48f825
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the domain 'easckaolp.myhome.cx'. This pattern is indicative of a link farm or a lure to a malicious site, likely intended to deceive users into downloading further malicious content or visiting phishing pages. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/6849848849845847/The-Nearly-Wed-Handbook-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/7840849847842847/Covenant-Discipleship-Parents-Handbook-The-Handbook-for-a-New-Sort-of-Communicants-Class-by-Richard-L-Burguet.pdf
    • http://easckaolp.myhome.cx/6849848849845841/Mr-Humblebrag-A-Parody-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845849/Quantitative-X-Ray-Diffractometry-by-Lev-S-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842845842840/The-Hole-We-re-in-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845844/Little-Miss-Basic-A-Parody-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/3842844849846844/All-These-Things-I-ve-Done-Birthright-1-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3849844847842848/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845849847848/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1840842845845/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842845846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1842846847845846/In-the-Age-of-Love-and-Chocolate-Birthright-3-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842840840/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845848846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845843/Into-adolescence-a-curriculum-for-grades-5-8-by-Dale-Zevin.pdf
    • http://easckaolp.myhome.cx/2848840840842844/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848848842840/A-Treasury-of-Chassidic-Tales-on-the-Torah-by-Shelomoh-Yosef-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849849840/The-New-Oxford-Picture-Dictionary-Beginners-Workbook-by-Patricia-E-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849846842/A-Greater-Good-Potentials-for-an-Intelligent-Economy-by-Robert-B-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849848849/A-Treasury-of-Chassidic-Tales-On-the-Torah----Volume-Two-by-Shlomo-Yosef-Zevin.pdf