Malicious PDF — malware analysis report

Static analysis result for SHA-256 9285fe234a65f6d4…

MALICIOUS

PDF

21.8 KB Created: 2020-03-20 16:50:35 +00:00 Authoring application: mPDF 5.7
MD5: a0267ba409947568de5126c02c98b5a3 SHA-1: 1d50002bebf0a2b0096200a423fdc619177f2a4a SHA-256: 9285fe234a65f6d4a24830117e0be9b4d573c4a3b606e3e6e5ac1c5e70be79d7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and a critical heuristic identified it as a link farm containing 27 external PDF links. The embedded links, such as http://eascasas.myhome.cx/4aa7aa0aa8aa1aa8/Ultimate-Plank-Fitness-For-a-Strong-Core-Killer-Abs---and-a-Killer-Body-by-Jen-DeCurtins.pdf, are likely intended to redirect users to malicious websites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/4aa7aa0aa8aa1aa8/Ultimate-Plank-Fitness-For-a-Strong-Core-Killer-Abs---and-a-Killer-Body-by-Jen-DeCurtins.pdf
    • http://eascasas.myhome.cx/1aa0aa9aa3aa8aa2aa0/Fitness-After-40-Your-Strong-Body-at-40-50-60-and-Beyond-by-Vonda-Wright.pdf
    • http://eascasas.myhome.cx/3aa3aa5aa4aa4aa9/The-Making-of-a-Serial-Killer-The-Real-Story-of-the-Gainesville-Student-Murders-in-the-Killer-s-Own-Words-True-Crime-Series-No-2-by-Danny-Rolling.pdf
    • http://eascasas.myhome.cx/2aa1aa2aa7aa0aa8/6-Killer-Bodies-Body-Movers-6-by-Stephanie-Bond.pdf
    • http://eascasas.myhome.cx/1aa7aa2aa4/Lady-Killer-Volume-1-Lady-Killer-1-by-Jo-lle-Jones.pdf
    • http://eascasas.myhome.cx/8aa7aa9aa4aa5aa1/The-Complete-John-Wayne-Cleaver-Series-I-Am-Not-a-Serial-Killer-Mr-Monster-I-Don-t-Want-to-Kill-You-Devil-s-Only-Friend-Over-Your-Dead-Body-Nothing-Left-to-Lose-by-Dan-Wells.pdf
    • http://eascasas.myhome.cx/2aa7aa9aa6aa3aa1/Serial-Killer-Quarterly-Vol-1-Christmas-Issue-quot-Body-Harvest-Prolific-American-Killers-quot-by-Kevin-M-Sullivan.pdf
    • http://eascasas.myhome.cx/1aa3aa2aa9aa1/Killer-Pizza-Killer-Pizza-1-by-Greg-Taylor.pdf
    • http://eascasas.myhome.cx/2aa9aa7aa7aa9aa9/Killer-Librarian-Killer-Librarian-1-by-Mary-Lou-Kirwin.pdf
    • http://eascasas.myhome.cx/3aa1aa5aa7aa8aa8/Ultimate-Kill-Ultimate-CORE-1-by-Kristine-Mason.pdf
    • http://eascasas.myhome.cx/1aa1aa9aa6aa8aa2aa7/Sound-Mind-Sound-Body-David-Kirsch-s-Ultimate-6-Week-Fitness-Transformation-for-Men-and-Women-by-David-Kirsch.pdf
    • http://eascasas.myhome.cx/7aa7aa2aa6aa2aa3/The-Pilates-Body-The-Ultimate-At-Home-Guide-to-Strengthening-Lengthening-and-Toning-Your-Body--Without-Machines-by-Brooke-Siler.pdf
    • http://eascasas.myhome.cx/3aa6aa4aa3aa8aa8/Paleo-Fitness-A-Primal-Training-and-Nutrition-Program-to-Get-Lean-Strong-and-Healthy-by-Darryl-Edwards.pdf
    • http://eascasas.myhome.cx/7aa7aa2aa6aa9aa4/The-Women-s-Health-Big-Book-of-Pilates-The-Essential-Guide-to-Total-Body-Fitness-by-Brooke-Siler.pdf
    • http://eascasas.myhome.cx/3aa2aa8aa8aa2aa3/The-Killer-by-Patr-cia-Melo.pdf
    • http://eascasas.myhome.cx/6aa5aa2aa5aa8aa8/Killer-Choice-by-Tom-Hunt.pdf
    • http://eascasas.myhome.cx/2aa1aa5aa4aa2aa6/If-I-Did-It-Confessions-of-the-Killer-by-O-J-Simpson.pdf
    • http://eascasas.myhome.cx/2aa9aa4aa8aa9aa4/A-Killer-Among-Us-by-Lynette-Eason.pdf
    • http://eascasas.myhome.cx/7aa1aa2aa3/The-Zodiac-Killer-by-W-L-Knightly.pdf
    • http://eascasas.myhome.cx/1aa1aa0aa3aa9aa6aa2/The-Catch-Me-Killer-by-Bob-Erler.pdf
    • http://eascasas.myhome.cx/8aa7aa9aa4aa5aa1/The-Complete-John-Wayne-Cleaver-Series-I-Am-Not-a-Serial-Killer-Mr-Monster-I-Don-t-Want-to-Kill-You-Devil-s-Only-Friend-Over-Your-Dead-Body-Nothing-