Malicious PDF — malware analysis report

Static analysis result for SHA-256 bcc2986e5860c903…

MALICIOUS

PDF

19.0 KB Created: 2020-02-06 02:44:04 +00:00 Authoring application: mPDF 5.7
MD5: ea37344e90cd1dabeb51a6568e900a0d SHA-1: d42f1190de96f5eb202527f8cbf14d613fee355d SHA-256: bcc2986e5860c90370772f4cc35c2e0de141b83c0194d67fed078ccf450e1a11
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, with the first URL being http://eascasas.myhome.cx/5aa6aa1aa2aa7aa3/Animal-Animal-1-by-Marni-Mann.pdf. This suggests the document's primary purpose is to direct users to a large collection of other documents, likely for SEO manipulation or to serve as a distribution point for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/5aa6aa1aa2aa7aa3/Animal-Animal-1-by-Marni-Mann.pdf
    • http://eascasas.myhome.cx/1aa8aa3aa4aa4aa3/Why-Animals-Matter-Animal-Consciousness-Animal-Welfare-and-Human-Well-Being-by-Marian-Stamp-Dawkins.pdf
    • http://eascasas.myhome.cx/2aa5aa5aa0aa1aa7/The-Animal-Rights-Handbook-Everyday-Ways-to-Save-Animal-Lives-by-Laura-Fraser.pdf
    • http://eascasas.myhome.cx/5aa6aa1aa9aa9/Animal-Moves-How-to-Move-Like-an-Animal-to-Get-You-Leaner-Fitter-Stronger-and-Healthier-for-Life-by-Darryl-Edwards.pdf
    • http://eascasas.myhome.cx/3aa1aa6aa5aa7aa4/The-Kitten-That-Won-First-Prize-And-Other-Animal-Stories-Animal-Ark-Special-1-by-Ben-M-Baglio.pdf
    • http://eascasas.myhome.cx/5aa0aa4aa9aa7aa9/Animal-Attraction-Animal-Magnetism-2-by-Jill-Shalvis.pdf
    • http://eascasas.myhome.cx/3aa0aa4aa3aa9aa7/Animal-Man-Volume-2-Animal-vs-Man-by-Jeff-Lemire.pdf
    • http://eascasas.myhome.cx/6aa4aa5aa6aa4aa7/Animal-Spirit-Guides-An-Easy-to-Use-Handbook-for-Identifying-and-Understanding-Your-Power-Animals-and-Animal-Spirit-Helpers-by-Steven-D-Farmer.pdf
    • http://eascasas.myhome.cx/7aa8aa6aa4aa5aa4/Making-Marvelous-Wooden-Puzzles-70-Animal-Families-70-Animal-Families-by-Saburo-Oguro.pdf
    • http://eascasas.myhome.cx/3aa1aa8aa6aa8aa9/Incredible-Animal-Dads-Fun-Animal-Books-For-Kids-With-Facts-amp-Incredible-Photos-Exploring-Our-Incredible-World-Children-s-Book-Series-by-Mark-Smith.pdf
    • http://eascasas.myhome.cx/3aa8aa6aa7aa8aa5/The-Unblocked-Collection-by-Marni-Mann.pdf
    • http://eascasas.myhome.cx/1aa1aa0aa8aa5aa4aa5/Pulled-Within-Bar-Harbor-2-by-Marni-Mann.pdf
    • http://eascasas.myhome.cx/1aa2aa0aa3aa6aa7/Animal-Magnetism-Animal-Magnetism-1-by-Jill-Shalvis.pdf
    • http://eascasas.myhome.cx/2aa2aa1aa5aa1aa7/Animal-Magnetism-Animal-Magnetism-1-by-Jill-Shalvis.pdf
    • http://eascasas.myhome.cx/3aa1aa5aa0aa8aa2/Seductive-Shadows-Shadows-1-by-Marni-Mann.pdf
    • http://eascasas.myhome.cx/2aa6aa4aa4aa4aa6/Man-The-Animal-The-Man-1-by-L-A-Morgan.pdf
    • http://eascasas.myhome.cx/1aa1aa8aa9aa7aa1aa3/What-Is-an-Animal-by-Tim-Ingold.pdf
    • http://eascasas.myhome.cx/5aa6aa1aa2aa7aa8/The-Last-Animal-by-Abby-Geni.pdf
    • http://eascasas.myhome.cx/5aa0aa9aa9aa2aa7/Animal-Antics-by-Janosch.pdf
    • http://eascasas.myhome.cx/2aa3aa9aa5aa6aa5/Tabby-in-the-Tub-Animal-Ark-29-by-Ben-M-Baglio.pdf
    • http://eascasas.myhome.cx/3aa0aa4aa3aa9aa7/Animal-Man-V