Malicious PDF — malware analysis report

Static analysis result for SHA-256 b232f476fb49243b…

MALICIOUS

PDF

18.8 KB Created: 2020-03-18 11:27:09 +00:00 Authoring application: mPDF 5.7
MD5: 9a3c57168959916abe9da03eb2132d88 SHA-1: cdd660fd11b91f7da9057881746aceaf8c9ad0f2 SHA-256: b232f476fb49243b28e60853990d3a44e5576d13e5d90bbb310480934059dde8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents on the domain easckaolp.myhome.cx. This is indicative of a link farm or a mechanism to distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/6842841844849840/So-ador-by-Manuel-Angel-Arrias.pdf
    • http://easckaolp.myhome.cx/1840847848840841845/Wander-Reiten-um-die-Welt-Oskar-reitet-in-Indien-Tibet-China-T-rkei-Nord-und-S-damerika-by-Manuel-Sauda-Sauda-Manuel.pdf
    • http://easckaolp.myhome.cx/3840845846849849/Angel-Surrogates-Chapter-1-Angel-Comic-01-Angel-Season-1-by-Christopher-Golden.pdf
    • http://easckaolp.myhome.cx/1841847841849848844/Battle-Angel-Alita-Barjack-Battle-Angel-Battle-Angel-Alita-Chapters-Battle-Angel-Alita-Characters-Battle-Angel-Alita-Images-by-Source-Wikia.pdf
    • http://easckaolp.myhome.cx/9846847845844840/Conversations-with-Manuel-Castells-by-Manuel-Castells.pdf
    • http://easckaolp.myhome.cx/3849845848846841/The-Angel-of-Death-Police-Snipers-amp-Hostage-Negotiators-Angel-Day-1-by-Blair-Babylon.pdf
    • http://easckaolp.myhome.cx/2845848841846840/Angel-in-My-Heart-Devil-in-My-Soul-Angel-Series-2-by-Linda-D-Hays-Gibbs.pdf
    • http://easckaolp.myhome.cx/3844848843843842/A-Date-With-Angel-And-Other-Things-That-Weren-t-Supposed-To-Happen-Kim-and-Angel-1-by-J-Judkins.pdf
    • http://easckaolp.myhome.cx/1840842844849843847/Battle-Angel-Alita---Last-Order-Angel-Redux-Vol-12-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/1840842844849844841/Battle-Angel-Alita---Last-Order-Angel-of-Defusion-Vol-14-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/1840842844849843846/Battle-Angel-Alita---Last-Order-Angel-Goes-Nova-Vol-10-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/1840842844848846844/Battle-Angel-Alita-Volume-06-Angel-Of-Death-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/1840842844849842845/Battle-Angel-Alita---Last-Order-Angel-of-Protest-Vol-04-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/7848844844844/Battle-Angel-Alita-Volume-05-Angel-Of-Redemption-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/1840842844848846848/Battle-Angel-Alita---Last-Order-Angel-of-the-Innocents-Vol-02-by-Yukito-Kishiro.pdf
    • http://easckaolp.myhome.cx/6843842842841/Dream-Angel-An-Angel-Novel-Series-Book-1-by-Jane-West.pdf
    • http://easckaolp.myhome.cx/4841843846846840/Angel-Dreams-An-Angel-Falls-2-by-Jody-A-Kessler.pdf
    • http://easckaolp.myhome.cx/1841848841843/Angel-Vindicated-Abby-Angel-1-by-Viola-Estrella.pdf
    • http://easckaolp.myhome.cx/4842841840845845/Angel-Falls-Josey-Angel-1-by-Derek-Catron.pdf
    • http://easckaolp.myhome.cx/1843845840843844/Her-Wicked-Angel-Her-Angel-6-by-Felicity-Heaton.pdf