Malicious PDF — malware analysis report

Static analysis result for SHA-256 5857815980d9b3a6…

MALICIOUS

PDF

21.4 KB Created: 2020-03-15 00:49:53 +00:00 Authoring application: mPDF 5.7
MD5: 214ff5def9004c1e0420f7af56908801 SHA-1: 168c20f21e183c391c2fa2e0251813b1b5763dbf SHA-256: 5857815980d9b3a6686c522a2bed56f9dd3b8bf2762208241020e6201a92cb72
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of external links, consistent with a link farm or SEO poisoning attack. The primary heuristic indicates a "PDF_SEO_LINK_FARM" with 26 external links, the first of which is http://eascasas.myhome.cx/1aa1aa8aa1aa3aa8aa4/Amazon-Echo-Amazon-Echo-Command-Guide-2016-Updated-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-by-Jamy-Jackson.pdf. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/1aa1aa8aa1aa3aa8aa4/Amazon-Echo-Amazon-Echo-Command-Guide-2016-Updated-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-by-Jamy-Jackson.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa1aa3aa3aa7/Amazon-Echo-Amazon-Echo-Advanced-User-Guide-2016-Updated-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-by-Jamy-Jackson.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa1aa3aa8aa3/Amazon-Dot-Niewbie-to-Expert-in-60-Minutes-on-Amazon-Dot-2nd-Generation-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-Book-3-by-Jamy-Jackson.pdf
    • http://eascasas.myhome.cx/4aa9aa9aa1aa4aa1/A-Narrative-Of-Travels-On-The-Amazon-And-Rio-Negro-With-An-Account-Of-The-Native-Tribes-And-Observations-On-The-Climate-Geology-And-Natural-History-Of-The-Amazon-Valley-by-Alfred-Russel-Wallace.pdf
    • http://eascasas.myhome.cx/1aa7aa4aa4aa3aa3/Echo-Queen-Echo-Trilogy-2-by-Lindsey-Fairleigh.pdf
    • http://eascasas.myhome.cx/9aa2aa0aa0aa7aa3/Echo-Desert-Run-Echo-3-by-Terry-Moore.pdf
    • http://eascasas.myhome.cx/2aa3aa0aa7aa3aa9/Amazon-Ink-Amazon-1-by-Lori-Devoti.pdf
    • http://eascasas.myhome.cx/1aa1aa5aa8aa2aa9aa0/Kindle-User-s-Guide-by-Amazon.pdf
    • http://eascasas.myhome.cx/4aa5aa7/Kindle-Paperwhite-User-s-Guide-by-Amazon.pdf
    • http://eascasas.myhome.cx/5aa2aa3aa4aa2aa2/Kindle-Voyage-User-s-Guide-by-Amazon.pdf
    • http://eascasas.myhome.cx/4aa5aa1aa9aa5aa7/Echo-Falls-Echo-Falls-1-by-Jaime-McDougall.pdf
    • http://eascasas.myhome.cx/1aa0aa0aa1aa4aa7aa4/Design-Your-Book-75-eBook-Cover-Design-Sites-That-Increase-Amazon-Sales-by-Greg-Strandberg.pdf
    • http://eascasas.myhome.cx/2aa4aa1aa7aa3aa7/Running-the-Amazon-by-Joe-Kane.pdf
    • http://eascasas.myhome.cx/2aa2aa5aa5aa2aa0/The-Amazon-Legion-by-Tom-Kratman.pdf
    • http://eascasas.myhome.cx/5aa7aa8aa2aa0aa8/To-Kindle-in-Ten-Steps-The-Easy-Way-to-Format-Create-and-Self-Publish-an-eBook-on-Amazon-s-Kindle-Direct-Publishing-by-M-A-Demers.pdf
    • http://eascasas.myhome.cx/1aa2aa9aa8aa2aa3/Amazon-Moon-by-James-A-Haught.pdf
    • http://eascasas.myhome.cx/9aa5aa0aa1aa7/Legends-of-the-Amazon-by-Vinicio-Ortiz.pdf
    • http://eascasas.myhome.cx/2aa5aa5aa5aa4/Amazon-Lily-by-Theresa-Weir.pdf
    • http://eascasas.myhome.cx/1aa0aa0aa9aa9aa5aa2/Programming-Amazon-EC2-by-Jurg-van-Vliet.pdf
    • http://eascasas.myhome.cx/1aa3aa8aa4aa9aa0/Dinner-Along-the-Amazon-by-Timothy-Findley.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa1aa3aa8aa3/Amazon-Dot-Niewbie-to-Expert-in-60-Minutes-on-Am