Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d3f8101d1e57fbc…

MALICIOUS

PDF

19.8 KB Created: 2020-03-18 16:41:30 +00:00 Authoring application: mPDF 5.7
MD5: e66d26fa5ab5009c566290443148777d SHA-1: da7d43f1b3c5d7e6ffb5809f24446842f7ac567b SHA-256: 9d3f8101d1e57fbcf7d3aed46ee36adaf4dea6f4409e882e701f9ca3b9377598
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly flagged this PDF as malicious. The primary purpose appears to be hosting a link farm, likely to redirect users to malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/2aa3aa8aa6aa1aa8/The-Hidden-Life-of-Deer-Lessons-from-the-Natural-World-by-Elizabeth-Marshall-Thomas.pdf
    • http://eascasas.myhome.cx/4aa7aa7aa2aa8aa7/The-Hidden-Life-of-Dogs-by-Elizabeth-Marshall-Thomas.pdf
    • http://eascasas.myhome.cx/2aa2aa0aa1aa2aa9/A-Million-Years-with-You-A-Memoir-of-Life-Observed-by-Elizabeth-Marshall-Thomas.pdf
    • http://eascasas.myhome.cx/2aa3aa8aa6aa3aa9/The-Animal-Wife-Reindeer-Moon-2-by-Elizabeth-Marshall-Thomas.pdf
    • http://eascasas.myhome.cx/2aa5aa8aa3aa7aa2/The-Tribe-of-Tiger-Cats-and-Their-Culture-by-Elizabeth-Marshall-Thomas.pdf
    • http://eascasas.myhome.cx/2aa0aa5aa8aa7aa2/Go-Kiss-the-World-Life-Lessons-For-The-Young-Professional-by-Subroto-Bagchi.pdf
    • http://eascasas.myhome.cx/3aa7aa2aa9aa6aa6/Gospel-According-to-Coco-Chanel-Life-Lessons-From-The-World-s-Most-Elegant-Woman-by-Karen-Karbo.pdf
    • http://eascasas.myhome.cx/8aa5aa1aa7aa4aa2/The-Inner-Life-of-Animals-Love-Grief-and-Compassion-Surprising-Observations-of-a-Hidden-World-by-Peter-Wohlleben.pdf
    • http://eascasas.myhome.cx/4aa2aa9aa1aa5aa8/The-Lakota-Way-Stories-and-Lessons-for-Living-by-Joseph-M-Marshall-III.pdf
    • http://eascasas.myhome.cx/1aa4aa2aa9aa3aa9/The-Lakota-Way-Stories-and-Lessons-for-Living-by-Joseph-M-Marshall-III.pdf
    • http://eascasas.myhome.cx/2aa5aa6aa2aa3aa8/The-Temptation-of-Elizabeth-Tudor-Elizabeth-I-Thomas-Seymour-and-the-Making-of-a-Virgin-Queen-by-Elizabeth-Norton.pdf
    • http://eascasas.myhome.cx/9aa1aa5aa9aa4aa0/A-Century-of-Wisdom-Lessons-from-the-Life-of-Alice-Herz-Sommer-the-World-s-Oldest-Living-Holocaust-Survivor-by-Caroline-Stoessinger.pdf
    • http://eascasas.myhome.cx/2aa5aa5aa5aa7aa4/Swimming-Lessons-Life-Lessons-from-the-Pool-from-Diving-in-to-Treading-Water-by-Penelope-Niven.pdf
    • http://eascasas.myhome.cx/2aa4aa1aa5aa4aa5/Soldier-Statesman-Peacemaker-Leadership-Lessons-from-George-C-Marshall-by-Jack-Uldrich.pdf
    • http://eascasas.myhome.cx/6aa3aa6aa7aa9/Lame-Deer-Seeker-of-Visions-by-John-Fire-Lame-Deer.pdf
    • http://eascasas.myhome.cx/2aa1aa2aa6aa9aa3/Changing-Grace-Beyond-Time-2-by-Elizabeth-Marshall.pdf
    • http://eascasas.myhome.cx/1aa0aa4aa5aa4aa2/Soldier-of-the-Legion-by-Marshall-S-Thomas.pdf
    • http://eascasas.myhome.cx/1aa0aa4aa6aa7aa2/Secret-of-the-Legion-by-Marshall-S-Thomas.pdf
    • http://eascasas.myhome.cx/5aa4aa9aa3aa1/Beyond-Time-Highland-Secret-Series-by-Elizabeth-Marshall.pdf
    • http://eascasas.myhome.cx/4aa1aa9aa4aa1/When-Fate-Dictates-Highland-Secrets-1-by-Elizabeth-Marshall.pdf
    • http://eascasas.myhome.cx/8aa