Malicious PDF — malware analysis report

Static analysis result for SHA-256 61a3d4de2bfba984…

MALICIOUS

PDF

14.5 KB Created: 2020-03-19 03:43:53 +00:00 Authoring application: mPDF 5.7
MD5: 7c605c88c1c35848e85ca8dfcca747e9 SHA-1: 3fece4524953c6073c2a07a150e4b4fb891b2cb7 SHA-256: 61a3d4de2bfba984e6d0792e8d39ec9259a008a801614321ade9f60f9630dba7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single suspicious domain, suggesting a link farm or a distribution point for further malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/8846842849849847/Red-Havoc-Guardian-Red-Havoc-Panthers-4-by-T-S-Joyce.pdf
    • http://easckaolp.myhome.cx/8846843840841842/Red-Havoc-Bad-Bear-Red-Havoc-Panthers-5-by-T-S-Joyce.pdf
    • http://easckaolp.myhome.cx/1844848847846846/Inevitable-Havoc-Havoc-2-by-Nina-Levine.pdf
    • http://easckaolp.myhome.cx/1844848848848846/Destined-Havoc-Havoc-1-by-Nina-Levine.pdf
    • http://easckaolp.myhome.cx/5846849840845845/Havoc-Havoc-1-by-Xavier-Neal.pdf
    • http://easckaolp.myhome.cx/1846847843845844/Havoc-Malice-2-by-Chris-Wooding.pdf
    • http://easckaolp.myhome.cx/3846842846846/Havoc-in-Its-Third-Year-by-Ronan-Bennett.pdf
    • http://easckaolp.myhome.cx/3840848844847843/Havoc-Series-Box-Set-by-Autumn-Grey.pdf
    • http://easckaolp.myhome.cx/3849847847847843/Playing-Havoc-by-Steve-Morris.pdf
    • http://easckaolp.myhome.cx/1842846849845849/Havoc-Deviants-2-by-Jeff-Sampson.pdf
    • http://easckaolp.myhome.cx/2847847844843846/Havoc-Dred-Chronicles-2-by-Ann-Aguirre.pdf
    • http://easckaolp.myhome.cx/4846848842848846/Havoc-The-Blackwell-Files-4-by-Steven-F-Freeman.pdf
    • http://easckaolp.myhome.cx/1844845840841840/Causing-Havoc-SBC-Fighters-1-by-Lori-Foster.pdf
    • http://easckaolp.myhome.cx/4843841841841847/Havoc-Philip-Mercer-7-by-Jack-Du-Brul.pdf
    • http://easckaolp.myhome.cx/3844847841847841/Havoc-Episode-Eight-The-Demon-Gate-8-by-Nicholas-Bella.pdf
    • http://easckaolp.myhome.cx/1841841845847849/Threads-That-Bind-Havoc-Chronicles-1-by-Brant-Williams.pdf
    • http://easckaolp.myhome.cx/1847842848842845/Havoc-s-Cry-Victoria-Novak-Paranormal-Division-by-Loren-Weaver.pdf
    • http://easckaolp.myhome.cx/4844847848842842/Einstein-Picasso-Space-Time-and-the-Beauty-That-Causes-Havoc-by-Arthur-I-Miller.pdf
    • http://easckaolp.myhome.cx/3848843840849841/Havoc-and-Hell-A-Dragon-s-Prize-Ethereal-Foes-3-by-Marie-Harte.pdf
    • http://easckaolp.myhome.cx/4846843846840845/Monkey-Makes-Havoc-In-Heaven-Monkey-Series-in-English-1-by-Xu-Li.pdf