Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d2bfe1754ffb4ff…

MALICIOUS

PDF

16.8 KB Created: 2020-03-18 21:14:55 +00:00 Authoring application: mPDF 5.7
MD5: 06df0cfc44c204c3e5e70ed8a67400c9 SHA-1: 59da832f5bb90586c358bd3d44e2968cba38750f SHA-256: 6d2bfe1754ffb4ffb9c333cd19b7dd6ce833ce5d71a65557150caf7eb690edec
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'easckaolp.myhome.cx'. This behavior is indicative of a link farm or a redirection scheme, likely intended to lead users to malicious content or phishing sites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/3845842845842840/The-Hole-We-re-in-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3842844849846844/All-These-Things-I-ve-Done-Birthright-1-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/9841846849843/Escape-to-Freedom-The-Story-of-Young-Frederick-Douglass-A-Play-for-Young-People-by-Ossie-Davis.pdf
    • http://easckaolp.myhome.cx/1842846847845846/In-the-Age-of-Love-and-Chocolate-Birthright-3-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845848846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/2848840840842844/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1847845849847848/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842845846849/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3849844847842848/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/1840842845845/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/3845842840840/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://easckaolp.myhome.cx/5843848842840/Hobby-The-Young-Merlin-Trilogy-2-by-Jane-Yolen.pdf
    • http://easckaolp.myhome.cx/6845844845849/Odysseus-in-the-Serpent-Maze-Young-Heroes-1-by-Jane-Yolen.pdf
    • http://easckaolp.myhome.cx/9849844847840842/Winning-Monologs-for-Young-Actors-65-Honest-To-Life-Characteriation-to-Delight-Young-Actors-and-Audiences-of-All-Ages-by-Peg-Kehret.pdf
    • http://easckaolp.myhome.cx/1840846842846848845/Young-Sexy-Babe---Book-454-Young-cute-chicks-sexy-photos-by-Johnny-Gunn.pdf
    • http://easckaolp.myhome.cx/5843847842840846/Star-of-the-Young-Pistolero-Young-Pistolero-Series-Book-2-by-Robert-J-Alvarado.pdf
    • http://easckaolp.myhome.cx/3842844842848/Manifestation-Wolverine-The-Collected-Poetry-of-Ray-Young-Bear-by-Ray-Young-Bear.pdf
    • http://easckaolp.myhome.cx/4846846846844/The-Young-Wizards-Young-Wizards-1-5-by-Diane-Duane.pdf
    • http://easckaolp.myhome.cx/1841842842846849/The-Young-World-The-Young-World-1-by-Chris-Weitz.pdf
    • http://easckaolp.myhome.cx/5848842844844842/Isolation-in-the-School-by-Ella-Flagg-Young-by-Ella-Flagg-Young.pdf