Malicious PDF — malware analysis report

Static analysis result for SHA-256 a642fba6ada8b177…

MALICIOUS

PDF

17.5 KB Created: 2020-03-15 21:25:53 +00:00 Authoring application: mPDF 5.7
MD5: 443a6a70adc90d788c71ef92647c6957 SHA-1: d40436b4926863acfed283412bf9bb15e2d642d2 SHA-256: a642fba6ada8b177572b1b1cdd9d153c0a7a902d34a59303a099a89484e95725
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain easckaolp.myhome.cx. This behavior is indicative of a link farm or a lure to download further malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the immediate intent beyond the link distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/6844845842843/Last-Days-by-Adam-Nevill.pdf
    • http://easckaolp.myhome.cx/4842844844841848/Some-Will-Not-Sleep-Selected-Horrors-by-Adam-Nevill.pdf
    • http://easckaolp.myhome.cx/5847842843848/His-Watchful-Eye-by-Jack-Cavanaugh.pdf
    • http://easckaolp.myhome.cx/2842846847841840/Darkness-amp-Daemons-The-Watchful-Invasion-2-by-M-T-Dismuke.pdf
    • http://easckaolp.myhome.cx/1840849842848846845/The-Balkans-A-History-of-Bulgaria-and-Serbia-by-Nevill-Forbes.pdf
    • http://easckaolp.myhome.cx/5846844846849/Billie-The-Nevill-Letters-1914-1916-by-Ruth-Elwin-Harris.pdf
    • http://easckaolp.myhome.cx/1840849842849842841/The-Balkans-A-History-of-Bulgaria-Serbia-Greece-Rumania-Turkey-by-Nevill-Forbes.pdf
    • http://easckaolp.myhome.cx/1840846843844847846/Watchful-Wisteria-Wisteria-Witches-4-by-Angela-Pepper.pdf
    • http://easckaolp.myhome.cx/9844841847849844/THE-OCTOBER-COUNTRY-The-Dwarf-The-Next-in-Line-The-Watchful-Poker-Chip-of-H-Matisse-Skeleton-The-Jar-The-Lake-The-Emissary-Touched-with-Fire-The-Small-Assassin-The-Crowd-Jack-in-the-Box-The-Scythe-Uncle-Einar-The-Wind-The-Man-Upstairs-by-Ray-Bradbury.pdf
    • http://easckaolp.myhome.cx/2847847846849840/Eve-amp-Adam-Eve-amp-Adam-1-by-Michael-Grant.pdf
    • http://easckaolp.myhome.cx/1849845842841843/Adam-Undercover-The-Presidium-Files-Adam-Undercover-1-by-Aaron-Foster.pdf
    • http://easckaolp.myhome.cx/4845849847847847/The-Poetical-Works-of-Adam-Lindsay-Gordon-by-Adam-Lindsay-Gordon.pdf
    • http://easckaolp.myhome.cx/8849847849844841/Adam-Smith-quot-Der-Wohlstand-der-Nationen-quot-by-Adam-Smith.pdf
    • http://easckaolp.myhome.cx/1846843848840843/On-by-Adam-Roberts.pdf
    • http://easckaolp.myhome.cx/6842840844848/Better-Out-Than-In-by-Adam-Wallace.pdf
    • http://easckaolp.myhome.cx/1841840843847849842/Adam-amp-Eve-by-Fohr.pdf
    • http://easckaolp.myhome.cx/1840844845849840/They-Both-Die-at-the-End-by-Adam-Silvera.pdf
    • http://easckaolp.myhome.cx/5841848841849842/Everything-We-Hoped-For-by-Pip-Adam.pdf
    • http://easckaolp.myhome.cx/6843844842841/They-Both-Die-at-the-End-by-Adam-Silvera.pdf
    • http://easckaolp.myhome.cx/7847847845847840/You-Don-t-See-Me-by-Adam-Duritz.pdf
    • http://easckaolp.myhome.cx/9844841847849844/THE-OCTOBER-COUNTRY-The-Dwarf-The-Next-in-Line-The-Watchful-Poker-Chip-of-H-Matisse-Skeleton-The-Jar-The-Lake-The-Emissary-Touched-with-Fire-T