Malicious PDF — malware analysis report

Static analysis result for SHA-256 28b0667398f8d0ff…

MALICIOUS

PDF

23.6 KB Created: 2020-03-18 16:39:16 +00:00 Authoring application: mPDF 5.7
MD5: 0d663245352cdf3c452065e4aecaf280 SHA-1: 5563d39447b648c5d32e281ab821a1631d02644d SHA-256: 28b0667398f8d0ff09838c9f75a0e38bf05cdf48ed3cd20f7cdc6fae7a3de65e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a domain hosting numerous potentially malicious or unwanted documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ewasocmo.myhome.cx/1c30c32c37c34c30c33/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Minecraft-Halloween-Curse---Part-One-Minecraft-Steve-and-Alex-Adventures-Book-10-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c33c39c37/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-2-Minecraft-Steve-and-Alex-Adventures-Book-8-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c33c39c36/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-1-Minecraft-Steve-and-Alex-Adventures-Book-7-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c34c30c31/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-3-Minecraft-Steve-and-Alex-Adventures-Book-9-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c31c35c32c36c32c30/Minecraft-Facts-Fun-Facts-Trivia-Tips-and-Tricks-for-Minecraft-by-Will-Karlsson.pdf
    • http://ewasocmo.myhome.cx/6c37c36c38c38/Herobrine-Rises-Season-One---Episode-0-Minecraft-Adventures-1-by-S-D-Stuart.pdf
    • http://ewasocmo.myhome.cx/1c37c36c32c33c31/Minecraft-Seeds-The-Top-25-Must-Have-Seeds-of-2015-by-Steve-Creepers.pdf
    • http://ewasocmo.myhome.cx/8c30c37c39c37c30/Flash-and-Bones-and-the-Empty-Tomb-of-Herobrine-Real-Comics-in-Minecraft---Flash-and-Bones-Book-1-by-Calvin-Crowther.pdf
    • http://ewasocmo.myhome.cx/8c30c37c39c37c34/Flash-and-Bones-and-Leetah-the-Wicked-Witch-Real-Comics-in-Minecraft---Flash-and-Bones-Book-2-by-Calvin-Crowther.pdf
    • http://ewasocmo.myhome.cx/8c30c33c37c35c38/Diary-of-a-Minecraft-Zombie-Book-13-Friday-Night-Frights-by-Zack-Zombie.pdf
    • http://ewasocmo.myhome.cx/8c30c33c37c35c35/Diary-of-a-Minecraft-Zombie-Book-12-Pixelmon-Gone-by-Zack-Zombie.pdf
    • http://ewasocmo.myhome.cx/1c30c39c37c30c30c34/Minecraft---Rezepte-f-r-Banner-und-Feuerwerk-by-Andreas-Zintzsch.pdf
    • http://ewasocmo.myhome.cx/5c35c35c32c36c31/Minecraft-Heroes-1-Bajan-Canadian-by-Mark-Ravion.pdf
    • http://ewasocmo.myhome.cx/1c38c30c39c35c32/KIDS-BOOKS-My-Minecraft-Escapades-by-Zach-King.pdf
    • http://ewasocmo.myhome.cx/1c31c34c36c30c38c33/Jay-Saves-the-Day-Unofficial-Minecraft-Early-Reader-Stories-1-by-Anna-Kopp.pdf
    • http://ewasocmo.myhome.cx/1c31c34c36c30c39c30/End-of-the-Dragon-Unofficial-Minecraft-Early-Reader-Stories-6-by-Anna-Kopp.pdf
    • http://ewasocmo.myhome.cx/1c31c34c36c33c39c39/Nether-Treasure-Unofficial-Minecraft-Early-Reader-Stories-3-by-Anna-Kopp.pdf
    • http://ewasocmo.myhome.cx/3c36c34c37c38c39/The-Crocodile-Hunter-The-Incredible-Life-and-Adventures-of-Steve-and-Terri-Irwin-by-Steve-Irwin.pdf
    • http://ewasocmo.myhome.cx/6c38c32c35c31c30/Return-of-the-Titans-The-Alex-Grosjean-Adventures-Book-3-by-Robin-Burks.pdf
    • http://ewasocmo.myhome.cx/1c31c34c36c30c38c35/Trapped-in-the-Tutorial-An-Unofficial-Minecraft-Glitcher-Novel-The-Glitcher-1-by-Anna-Kopp.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c33c39c36/Action-Comics-The-Minecraft-Adven