Malicious PDF — malware analysis report

Static analysis result for SHA-256 98d472ca876a4d7e…

MALICIOUS

PDF

16.1 KB Created: 2020-03-18 22:32:13 +00:00 Authoring application: mPDF 5.7
MD5: f5073cc473b8bb7f47e17ebea4bb7848 SHA-1: 5a9b6e51f7312e49a3bb4355be6e3806c445cede SHA-256: 98d472ca876a4d7ea5929e6cd92c049d2be51b463ec48a9e588e3e33451137c0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, all hosted on the domain easckaolp.myhome.cx. This behavior is indicative of a link farm or a distribution point for further malicious content. No scripts were extracted, and the document body was heavily obfuscated, but the heuristic firings strongly suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/3843849843845848/Kanyakumari-by-Hazel-Manuel.pdf
    • http://easckaolp.myhome.cx/1841842841842843849/Kiss-of-the-Spider-Woman-and-Two-Other-Plays-by-Manuel-Puig.pdf
    • http://easckaolp.myhome.cx/1840847848840841845/Wander-Reiten-um-die-Welt-Oskar-reitet-in-Indien-Tibet-China-T-rkei-Nord-und-S-damerika-by-Manuel-Sauda-Sauda-Manuel.pdf
    • http://easckaolp.myhome.cx/8846840849846/The-Hazel-Wood-The-Hazel-Wood-1-by-Melissa-Albert.pdf
    • http://easckaolp.myhome.cx/4849849840849846/Something-s-Fishy-Hazel-Green-Hazel-Green-2-by-Odo-Hirsch.pdf
    • http://easckaolp.myhome.cx/8844849844844846/Geranium-by-Kasia-Boddy.pdf
    • http://easckaolp.myhome.cx/8844849844846843/The-Geranium-Stair-by-Rosemary-Rome.pdf
    • http://easckaolp.myhome.cx/4841846844846845/Magical-Geranium-by-Barbara-Sala.pdf
    • http://easckaolp.myhome.cx/8844849842848848/The-Geranium-Window-by-Beatrice-MacNeil.pdf
    • http://easckaolp.myhome.cx/8844849842848847/The-Geranium-Girls-by-Alison-Preston.pdf
    • http://easckaolp.myhome.cx/8842847844842847/Stick-a-Geranium-in-Your-Hat-and-Be-Happy-by-Barbara-Johnson.pdf
    • http://easckaolp.myhome.cx/3848845847847848/Any-Man-s-Death-Hazel-Holt-by-Hazel-Holt.pdf
    • http://easckaolp.myhome.cx/8845846841843/The-Blue-Geranium-A-Short-Story-by-Agatha-Christie.pdf
    • http://easckaolp.myhome.cx/1840841849843840/The-Geranium-on-the-Windowsill-Just-Died-But-Teacher-You-Went-Right-on-by-Albert-Cullum.pdf
    • http://easckaolp.myhome.cx/8844849843844843/The-Nightmares-of-Geranium-Street-by-Susan-Richards-Shreve.pdf
    • http://easckaolp.myhome.cx/8844849845849848/From-the-Geranium-Farm-A-Second-Crop-of-Daily-Emails-by-Barbara-Cawthorne-Crafton.pdf
    • http://easckaolp.myhome.cx/9846847845844840/Conversations-with-Manuel-Castells-by-Manuel-Castells.pdf
    • http://easckaolp.myhome.cx/8844849845849849/Easy-and-Simple-Geranium-Care---A-Guide-to-Growing-Gorgeous-Geraniums-by-Kris-Maher.pdf
    • http://easckaolp.myhome.cx/4848848849841842/Qur-an-and-Woman-Rereading-the-Sacred-Text-from-a-Woman-s-Perspective-by-Amina-Wadud.pdf
    • http://easckaolp.myhome.cx/1848845849847/A-Woman-s-Passion-for-Travel-More-Stories-from-a-Woman-s-World-by-Marybeth-Bond.pdf
    • http://easckaolp.myhome.cx/8842847844842847/Stick-a-Geranium-in-Your-Hat-and