Malicious PDF — malware analysis report

Static analysis result for SHA-256 2aaf3814ee007da3…

MALICIOUS

PDF

20.4 KB Created: 2020-03-20 16:19:20 +00:00 Authoring application: mPDF 5.7
MD5: 84002d8cf7d664fd10f2aae1e4a05d22 SHA-1: 567d5a551fc090e80633839c4663382dc706c45a SHA-256: 2aaf3814ee007da3b5aa6ce0de4048cb0f4996fac47e3f14a717b5377448cf36
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF documents hosted on eascasas.myhome.cx. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm designed to lure users to potentially malicious or phishing content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/3aa4aa5aa5aa7/A-Different-Mirror-A-History-of-Multicultural-America-by-Ronald-Takaki.pdf
    • http://eascasas.myhome.cx/2aa8aa1aa7aa9/Strangers-from-a-Different-Shore-A-History-of-Asian-Americans-by-Ronald-Takaki.pdf
    • http://eascasas.myhome.cx/4aa5aa2aa9aa6aa2/Unequal-Sisters-A-Multicultural-Reader-in-U-S-Women-s-History-by-Vicki-L-Ruiz.pdf
    • http://eascasas.myhome.cx/8aa6aa8aa8aa0/Morning-in-America-How-Ronald-Reagan-Invented-the-1980-s-by-Gil-Troy.pdf
    • http://eascasas.myhome.cx/1aa1aa5aa3aa3aa7aa4/Tomorrow-the-World-Hitler-Northwest-Africa-and-the-Path-Toward-America-by-Ronald-A-Schorn.pdf
    • http://eascasas.myhome.cx/7aa4aa4aa5aa3aa9/The-Mirror-A-History-by-Sabine-Melchior-Bonnet.pdf
    • http://eascasas.myhome.cx/9aa2aa0aa3aa7/A-Short-History-of-Progress-by-Ronald-Wright.pdf
    • http://eascasas.myhome.cx/2aa1aa6aa0aa9aa7/The-Stations-of-the-Sun-A-History-of-the-Ritual-Year-in-Britain-by-Ronald-Hutton.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa0aa4aa1aa6/Behind-the-Mirror-A-Search-for-a-Natural-History-of-Human-Knowledge-by-Konrad-Lorenz.pdf
    • http://eascasas.myhome.cx/4aa0aa2aa2aa4aa0/Blood-of-Spain-An-Oral-History-of-the-Spanish-Civil-War-by-Ronald-Fraser.pdf
    • http://eascasas.myhome.cx/2aa5aa8aa3aa6aa7/An-Economic-History-of-the-United-States-From-1607-to-the-Present-by-Ronald-E-Seavoy.pdf
    • http://eascasas.myhome.cx/5aa1aa1aa9aa5aa6/The-Routledge-History-of-Literature-in-English-Britain-and-Ireland-by-Ronald-Carter.pdf
    • http://eascasas.myhome.cx/1aa9aa7aa4aa4aa9/Miners-Millhands-and-Mountaineers-Industrialization-of-the-Appalachian-South-1880-1930-Twentieth-Century-America-Series-by-Ronald-D-Eller.pdf
    • http://eascasas.myhome.cx/4aa9aa4aa7aa4aa2/Orielton-The-Human-and-Natural-History-of-a-Welsh-Manor-by-Ronald-Mathias-Lockley.pdf
    • http://eascasas.myhome.cx/5aa0aa9aa3aa4aa9/The-History-of-the-British-Petroleum-Company-Volume-1-The-Developing-Years-1901-1932-by-Ronald-W-Ferrier.pdf
    • http://eascasas.myhome.cx/4aa7aa5aa5aa2aa4/Reagan-In-His-Own-Hand-The-Writings-of-Ronald-Reagan-that-Reveal-His-Revolutionary-Vision-for-America-by-Kiron-K-Skinner.pdf
    • http://eascasas.myhome.cx/1aa0aa7aa1aa0aa1aa9/Unveiled-Whistleblower-Mirror-Mirror-Lover-Stranger-by-Tess-Gerritsen.pdf
    • http://eascasas.myhome.cx/8aa6aa7aa5aa4/Mirror-Mirror-on-the-Wall-The-Diary-of-Bess-Brennan-by-Barry-Denenberg.pdf
    • http://eascasas.myhome.cx/2aa7aa5aa4aa0aa2/Mirror-Mirror-on-the-Wall-Women-Writers-Explore-Their-Favorite-Fairy-Tales-by-Kate-Bernheimer.pdf
    • http://eascasas.myhome.cx/1aa0aa5aa9aa6/Mirror-Mirror-A-Book-of-Reverso-Poems-by-Marilyn-Singer.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa0aa4aa1aa6/Behind-the-Mirror-A-Search-for-a-Natu