Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab4e5c6cd745bb71…

MALICIOUS

PDF

20.5 KB Created: 2020-03-16 04:47:29 +00:00 Authoring application: mPDF 5.7
MD5: f0fe990d310167c78a84ff4dfcaa15cd SHA-1: a7c565d458081d5244a68535f538141502f23847 SHA-256: ab4e5c6cd745bb71a5125c451dc464a96a033249f6c9273cc14e5079c3d65b84
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to a single domain, indicative of a link farm. This heuristic, combined with the ML classifier's high confidence, suggests a malicious intent to redirect users. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/2aa0aa7aa8aa3aa8/Lost-Soul-Harbinger-P-I-1-by-Adam-J-Wright.pdf
    • http://eascasas.myhome.cx/3aa0aa7aa4aa7aa9/Harbinger-of-Justice-Harbinger-Witches-1-by-Savannah-Morgan.pdf
    • http://eascasas.myhome.cx/2aa2aa9aa9aa7aa9/Harbinger-of-Doom---Gateway-Edition-The-Harbinger-of-Doom-Saga-1-novella-length-2-by-Glenn-G-Thater.pdf
    • http://eascasas.myhome.cx/3aa6aa7aa6aa8aa7/Soul-of-Dust-by-Adam-Millard.pdf
    • http://eascasas.myhome.cx/9aa7aa4aa4aa6aa7/Lost-Cappuccino-Heaven-2-by-Michelle-Wright.pdf
    • http://eascasas.myhome.cx/2aa1aa5aa8aa9aa7/Lost-Girl-by-Adam-Nevill.pdf
    • http://eascasas.myhome.cx/5aa0aa0aa5aa8aa2/Lost-Soul-by-Chayil-Champion.pdf
    • http://eascasas.myhome.cx/7aa7aa9aa0aa3aa3/NU-Soul-Album-de-NU-Soul-Artiste-de-Neo-Soul-Tournee-de-NU-Soul-Alicia-Keys-Liste-Des-Recompenses-Et-Nominations-D-Alicia-Keys-Mama-s-Gun-the-Diary-of-Alicia-Keys-Common-Corinne-Bailey-Rae-Unplugged-D-Angelo-Lauryn-Hill-Neo-Soul-by-Source-Wikipedia.pdf
    • http://eascasas.myhome.cx/1aa1aa5aa7aa9aa9/The-Lost-Soul-Trilogy-Primani-1-3-by-Laurie-Olerich.pdf
    • http://eascasas.myhome.cx/6aa1aa7aa5aa7/The-Lost-Soul-Fallen-Souls-1-by-Jessica-Sorensen.pdf
    • http://eascasas.myhome.cx/4aa6aa8aa0aa7aa8/The-Lost-Soul-The-Raven-Saga-3-by-Suzy-Turner.pdf
    • http://eascasas.myhome.cx/3aa4aa1aa0aa4aa9/Primal-A-Quest-for-the-Lost-Soul-of-Christianity-by-Mark-Batterson.pdf
    • http://eascasas.myhome.cx/1aa0aa9aa1aa4aa5aa2/Joe-Carpenter-and-the-Soul-Of-The-Lost-Artefact-A-Mystery-Adventure-Novel-by-Michael-Greaves.pdf
    • http://eascasas.myhome.cx/4aa7aa5aa7aa7/Chicken-Soup-for-the-Teenage-Soul-The-Real-Deal-Friends-Best-Worst-Old-New-Lost-False-True-and-More-by-Jack-Canfield.pdf
    • http://eascasas.myhome.cx/4aa6aa1aa2aa3aa6/The-Lost-Soul-Companion-A-Book-of-Comfort-and-Constructive-Advice-for-Black-Sheep-Square-Pegs-Struggling-Artists-and-Other-Free-Spirits-by-Susan-M-Brackney.pdf
    • http://eascasas.myhome.cx/1aa1aa3aa8aa6aa7aa2/Russel-Wright-s-Menu-Cookbook-A-Guide-to-Easier-Entertaining-by-Ann-Wright.pdf
    • http://eascasas.myhome.cx/6aa3aa6aa6aa5aa3/Adam-s-Tiger-Adam-s-Chronicles-Book-3-by-Lawrence-Lapin.pdf
    • http://eascasas.myhome.cx/3aa7aa5aa6aa3aa9/Harbinger---Episode-I-by-Angelo-Tsanatelis.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa8aa4aa5/The-Harbinger-The-Apocalypse-1-by-Caitlin-White.pdf
    • http://eascasas.myhome.cx/1aa5aa7aa8aa9aa3/A-Harbinger-s-Tale-by-Dale-W-Reierson.pdf
    • http://eascasas.myhome.cx/7aa7aa9aa0aa3aa3/NU-Soul-Album-de-NU-Soul-Artiste-de-Neo-Soul-Tournee-de-NU-Soul-Alicia-Keys-Liste-Des-Recompenses-Et-Nominations-D-Alicia-K