Malicious PDF — malware analysis report

Static analysis result for SHA-256 c10db10321fb737f…

MALICIOUS

PDF

23.6 KB Created: 2020-03-15 00:50:43 +00:00 Authoring application: mPDF 5.7
MD5: fb9dae146f2a796f9aa2896e06dd7346 SHA-1: 6a603d80eba526b9d03b3df0bd2a1cda554ed4a8 SHA-256: c10db10321fb737f06295cd6613ea5e129d4691e37ca8a56ea0a9b0f7777ae23
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The URLs point to a domain with a suspicious structure, suggesting a link farm or a distribution point for further malicious content. No scripts were extracted, but the PDF structure itself is indicative of a malicious distribution pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/3aa5aa2aa5aa5aa6/The-New-Woman-s-Hour-Book-Of-Short-Stories-by-Di-Speirs.pdf
    • http://eascasas.myhome.cx/3aa2aa5aa3aa6aa7/You-Can-t-Keep-a-Good-Woman-Down-Short-Stories-by-Alice-Walker.pdf
    • http://eascasas.myhome.cx/2aa2aa1aa6aa3aa3/A-Day-in-the-Life-of-a-Smiling-Woman-Complete-Short-Stories-by-Margaret-Drabble.pdf
    • http://eascasas.myhome.cx/3aa8aa4aa7aa5/The-Woman-Who-Married-a-Cloud-The-Collected-Short-Stories-by-Jonathan-Carroll.pdf
    • http://eascasas.myhome.cx/3aa1aa3aa2aa7aa5/Short-Stories-for-Early-Readers-17-Short-Stories-Included-Tall-Tales-Kids-Story-Bundle-Childrens-ebooks-Short-Story-Series-Diaries-of-Simple-Reading-by-Betty-J-Byers.pdf
    • http://eascasas.myhome.cx/8aa2aa5aa6aa7aa0/The-Voice-Of-The-Voiceless-A-Delacourt-Short-Story-The-Delacourt-Short-Stories-Book-1-by-S-A-Tedman.pdf
    • http://eascasas.myhome.cx/9aa9aa3aa7aa0aa8/Great-American-Short-Stories-vol-1-The-Birthmark-The-Threefold-Destiny-An-Old-Woman-s-Tale-by-Nathaniel-Hawthorne.pdf
    • http://eascasas.myhome.cx/7aa3aa4aa3aa6aa9/Edition-1nd-Just-1-hour-Amazing-Singapore-Travelling-Book-Bring-this-book-to-travel-This-book-is-NEW-This-book-includes-7-important-expression-for-this-book-by-Takuji.pdf
    • http://eascasas.myhome.cx/1aa9aa1aa4aa5/Diva-Book-of-Short-Stories-by-Helen-Sandler.pdf
    • http://eascasas.myhome.cx/3aa2aa5aa3aa7aa7/The-New-Penguin-Book-of-Scottish-Short-Stories-by-Ian-Murray.pdf
    • http://eascasas.myhome.cx/3aa1aa3aa2aa8aa2/Short-Elementary-Level-Stories-Bundle-5-3-Short-Stories-in-1-Ebook-Books-about-love-signing-baby-animals-school-planets-family-Perfect-for-kids-under-10-learning-to-read-by-Betty-J-Byers.pdf
    • http://eascasas.myhome.cx/3aa2aa7aa4aa3aa4/Penguin-Book-Of-Irish-Short-Stories-by-Benedict-Kiely.pdf
    • http://eascasas.myhome.cx/3aa2aa7aa6aa8aa6/The-Penguin-Book-of-English-Short-Stories-by-Christopher-Dolley.pdf
    • http://eascasas.myhome.cx/3aa8aa8aa0aa9aa0/The-Oxford-Book-Of-Japanese-Short-Stories-by-Theodore-W-Goossen.pdf
    • http://eascasas.myhome.cx/3aa8aa7aa9aa3aa7/Tangerine-City-A-Book-of-Twenty-Short-Stories-by-Hilary-West.pdf
    • http://eascasas.myhome.cx/9aa5aa2aa3aa8/Dreams-of-Love-A-Book-of-Poems-and-Short-Stories-by-Carla-Golian.pdf
    • http://eascasas.myhome.cx/3aa8aa7aa5aa8aa6/The-Silk-Peacock-A-Book-of-Twenty-Short-Stories-by-Hilary-West.pdf
    • http://eascasas.myhome.cx/4aa4aa5aa0aa7aa2/The-Penguin-Book-Of-Modern-Women-s-Short-Stories-by-Susan-Hill.pdf
    • http://eascasas.myhome.cx/7aa3aa4aa6aa6aa0/2nd-Edition-Just-1-hour-Amazing-Saipan-Travelling-Book-Bring-this-book-to-travel-This-book-is-This-book-includes-7-important-expression-for-travelling-countries-with-this-book-by-Takuji-Ekawa.pdf
    • http://eascasas.myhome.cx/7aa3aa4aa5aa7aa0/Edition-1nd-Just-1-hour-Amazing-Hawaii-Travelling-Book-Bring-this-book-to-travel-This-book-is-NEW-This-book-includes-7-important-expression-for-travelling-this-book-by-Takuji-Ekawa.pdf