Malicious PDF — malware analysis report

Static analysis result for SHA-256 a16072e2e433ac53…

MALICIOUS

PDF

26.1 KB Created: 2020-03-18 21:17:34 +00:00 Authoring application: mPDF 5.7
MD5: 854c2c528c4ed9c6238c49f4c956bd74 SHA-1: f3dfc6d8d4d1a483b61ff97980f895c080eeabfc SHA-256: a16072e2e433ac532c65c39813e8d8cee322c11c27aa469f10cb23b9f758923d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'ewasocmo.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ewasocmo.myhome.cx/6c37c36c38c38/Herobrine-Rises-Season-One---Episode-0-Minecraft-Adventures-1-by-S-D-Stuart.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c34c30c33/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Minecraft-Halloween-Curse---Part-One-Minecraft-Steve-and-Alex-Adventures-Book-10-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c33c39c36/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-1-Minecraft-Steve-and-Alex-Adventures-Book-7-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c34c30c31/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-3-Minecraft-Steve-and-Alex-Adventures-Book-9-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c33c39c37/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-2-Minecraft-Steve-and-Alex-Adventures-Book-8-by-Anneline-Kinnear.pdf
    • http://ewasocmo.myhome.cx/8c30c37c39c37c30/Flash-and-Bones-and-the-Empty-Tomb-of-Herobrine-Real-Comics-in-Minecraft---Flash-and-Bones-Book-1-by-Calvin-Crowther.pdf
    • http://ewasocmo.myhome.cx/2c31c37c36c31c30/The-Spiral-Arm-episode-1-season-1-by-Peter-Boland.pdf
    • http://ewasocmo.myhome.cx/2c30c33c38c35c36/Graveyard-of-Dreams-The-Dream-Killers-Season-1-Episode-1-by-S-M-Blooding.pdf
    • http://ewasocmo.myhome.cx/3c34c37c37c32c30/Retribution-Episode-One-of-Season-Four-The-Kingdom-of-Ara-The-New-Haven-Series-Book-16-by-Nicholas-Bella.pdf
    • http://ewasocmo.myhome.cx/4c32c35c37c34c32/Jewel-of-The-Stars---Season-1-Episode-1---Earth-s-Remnant-by-Adam-David-Collings.pdf
    • http://ewasocmo.myhome.cx/1c31c35c32c36c32c30/Minecraft-Facts-Fun-Facts-Trivia-Tips-and-Tricks-for-Minecraft-by-Will-Karlsson.pdf
    • http://ewasocmo.myhome.cx/8c35c33c34c37c37/Fatal-Episode-2-Season-1-Alexa-Guerra---The-Female-Jack-Reacher-Fatal---The-Series-by-Arno-Joubert.pdf
    • http://ewasocmo.myhome.cx/3c32c35c31c32c32/The-Further-Adventures-of-Sherlock-Holmes-The-Albino-s-Treasure-by-Stuart-Douglas.pdf
    • http://ewasocmo.myhome.cx/2c33c32c33c34c38/The-Further-Adventures-of-Sherlock-Holmes---The-Counterfeit-Detective-by-Stuart-Douglas.pdf
    • http://ewasocmo.myhome.cx/1c35c39c39c33c35/The-Adventures-of-Armstrong-Dent-The-Complete-First-Season-by-Aeyess.pdf
    • http://ewasocmo.myhome.cx/2c33c37c30c37c37/The-Further-Adventures-of-Sherlock-Holmes-The-Scroll-of-the-Dead-by-David-Stuart-Davies.pdf
    • http://ewasocmo.myhome.cx/6c35c33c32c36c36/--season-II-14-Rozario-to-Banpaia-Season-II-14-Rosario-Vampire-Season-II-14-by-Akihisa-Ikeda.pdf
    • http://ewasocmo.myhome.cx/1c37c32c39c39c32/The-Sky-Crawlers-Episode-2-Episode-3-by-Hiroshi-Mori.pdf
    • http://ewasocmo.myhome.cx/1c30c33c33c31c37c36/Palm-South-University-Season-2-Episode-2-Palm-South-University-2-2-by-Kandi-Steiner.pdf
    • http://ewasocmo.myhome.cx/1c30c33c33c30c35c35/Palm-South-University-Season-2-Episode-1-Palm-South-University-2-2-by-Kandi-Steiner.pdf
    • http://ewasocmo.myhome.cx/1c30c32c37c34c30c31/Action-Comics-The-Minecraft-Adv