Malicious PDF — malware analysis report

Static analysis result for SHA-256 503901180a9da5f9…

MALICIOUS

PDF

20.0 KB Created: 2020-03-18 22:40:55 +00:00 Authoring application: mPDF 5.7
MD5: f68c3e5a2525decf6fe4d92344892987 SHA-1: 67615bac586bc4d37621786877e09168cdbea68e SHA-256: 503901180a9da5f934b971ce1befb849399a0ddf76399cad23dd0b4ceefa38ab
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and a critical heuristic for containing a large number of external links. The document body consists primarily of these embedded URLs, suggesting a link farm or redirection mechanism. The primary purpose appears to be directing users to potentially malicious content hosted on 'ewasocmo.myhome.cx'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ewasocmo.myhome.cx/3c35c33c31c39c34/Wings-Subversive-Gay-Angel-Erotica-by-Todd-Gregory.pdf
    • http://ewasocmo.myhome.cx/3c38c30c33c33c35/Midnight-Hunger-by-Todd-Gregory.pdf
    • http://ewasocmo.myhome.cx/3c35c33c31c36c38/Blood-Sacraments-by-Todd-Gregory.pdf
    • http://ewasocmo.myhome.cx/1c33c35c30c35c32/Wings-of-Fire-Inspector-Ian-Rutledge-2-by-Charles-Todd.pdf
    • http://ewasocmo.myhome.cx/8c30c37c39c34/Colorado-Wings-A-Wing-and-a-Prayer-Wings-Like-Eagles-Wings-of-the-Dawn-A-Gift-of-Wings-by-Tracie-Peterson.pdf
    • http://ewasocmo.myhome.cx/4c37c30c39c31c31/On-Angel-s-Wings-by-Nikki-Prince.pdf
    • http://ewasocmo.myhome.cx/4c35c38c35c31c31/Angel-Wings-by-Nadeem-Fraz.pdf
    • http://ewasocmo.myhome.cx/1c30c38c35c32c33c33/Angel-Joins-In-And-It-s-Suddenly-a-Threesome-An-FFM-M-nage-a-Trois-Erotica-Story-by-Geena-Flix.pdf
    • http://ewasocmo.myhome.cx/6c32c32c30c35c31/Wings-Concert-Tours-Wings-Over-the-World-Tour-Wings-Over-Europe-Tour-Concerts-for-the-People-of-Kampuchea-Wings-UK-Tour-1979-by-Books-LLC.pdf
    • http://ewasocmo.myhome.cx/6c35c38c33c36c38/Butterfly-wings-and-dragonfly-wings-Guardian-Fairy-Book-7-by-Anastasia-Ducret.pdf
    • http://ewasocmo.myhome.cx/3c30c35c36c39c39/Angel-Surrogates-Chapter-1-Angel-Comic-01-Angel-Season-1-by-Christopher-Golden.pdf
    • http://ewasocmo.myhome.cx/1c31c36c32c31c36/Broken-Wings-Hidden-Wings-2-by-Cameo-Renae.pdf
    • http://ewasocmo.myhome.cx/2c30c30c39c33c33/Dark-Wings-Descending-Wings-1-by-Lesley-Davis.pdf
    • http://ewasocmo.myhome.cx/3c35c31c38c33c36/Dark-Wings-Descending-Wings-1-by-Lesley-Davis.pdf
    • http://ewasocmo.myhome.cx/3c35c32c39c32c35/The-Union-Club-A-Subversive-Thriller-by-Don-Winston.pdf
    • http://ewasocmo.myhome.cx/7c34c32c31c36/Rebels-Wit-Attitude-Subversive-Rock-Humorists-by-Iain-Ellis.pdf
    • http://ewasocmo.myhome.cx/4c31c30c37c30c38/Wings-Wings-1-by-Aprilynne-Pike.pdf
    • http://ewasocmo.myhome.cx/2c39c38c36c38c30/A-Field-Guide-to-Demons-Fairies-Fallen-Angels-and-Other-Subversive-Spirits-by-Carol-K-Mack.pdf
    • http://ewasocmo.myhome.cx/1c30c38c35c32c34c31/My-Boss-Marilyn-And-My-New-Extra-Job-Duties-A-Lesbian-Seduction-Erotica-Story-A-Lesbian-Seduction-Erotica-Story-by-Geena-Flix.pdf
    • http://ewasocmo.myhome.cx/1c31c37c31c39c38c34/Battle-Angel-Alita-Barjack-Battle-Angel-Battle-Angel-Alita-Chapters-Battle-Angel-Alita-Characters-Battle-Angel-Alita-Images-by-Source-Wikia.pdf
    • http://ewasocmo.myhome.cx/6c32c32c30c35c31/Wings-Concert-Tours-Wings-Over-the-World-Tour-Wings-Over-Eur