Malicious PDF — malware analysis report

Static analysis result for SHA-256 30038f078249bc8b…

MALICIOUS

PDF

16.5 KB Created: 2020-03-18 20:30:24 +00:00 Authoring application: mPDF 5.7
MD5: 00b9fbb54323f2a2f5eaae53420f5cd5 SHA-1: 05115b1a803054682bbde72eed02ea946bc5487e SHA-256: 30038f078249bc8b3b48900a941f4be0b29f02044c78c11e87979bcd6b8622e0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, such as http://easckaolp.myhome.cx/6849848849845849/Quantitative-X-Ray-Diffractometry-by-Lev-S-Zevin.pdf, are likely used to direct users to malicious websites or for SEO spamming purposes. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/6849848849845849/Quantitative-X-Ray-Diffractometry-by-Lev-S-Zevin.pdf
    • http://easckaolp.myhome.cx/9842849849848849/Quantitative-Pharmaceutical-Chemistry-by-Adelbert-M-Knevel.pdf
    • http://easckaolp.myhome.cx/6841844841845/The-Visual-Display-of-Quantitative-Information-by-Edward-R-Tufte.pdf
    • http://easckaolp.myhome.cx/1840849842840845849/Quantitative-Analysis-of-Drugs-in-Pharmaceutical-Formulations-by-P-D-Sethi.pdf
    • http://easckaolp.myhome.cx/6844842843846846/Epidemiologic-Research-Principles-and-Quantitative-Methods-by-David-G-Kleinbaum.pdf
    • http://easckaolp.myhome.cx/7849848841845841/Quantitative-Portfolio-Optimisation-Asset-Allocation-and-Risk-Management-by-Mikkel-Rasmussen.pdf
    • http://easckaolp.myhome.cx/6849848849845847/The-Nearly-Wed-Handbook-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845841/Mr-Humblebrag-A-Parody-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842845842840/The-Hole-We-re-in-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3842844849846844/All-These-Things-I-ve-Done-Birthright-1-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845844/Little-Miss-Basic-A-Parody-by-Dan-Zevin.pdf
    • http://easckaolp.myhome.cx/9841848849844847/Flavour-Science-Chapter-99-Quantitative-Mapping-of-Taste-Active-Compounds-in-Dashi-Ingredients-by-Gesa-Haseleu.pdf
    • http://easckaolp.myhome.cx/3849844847842848/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842840840/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845849847848/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/2848840840842844/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1842846847845846/In-the-Age-of-Love-and-Chocolate-Birthright-3-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/6849848849845843/Into-adolescence-a-curriculum-for-grades-5-8-by-Dale-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845848846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842845846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhom