Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7c73738407ba77e…

MALICIOUS

PDF

23.9 KB Created: 2020-02-14 19:25:09 +00:00 Authoring application: mPDF 5.7
MD5: d08668c8fa7ace62f527f1f23f029137 SHA-1: af327544f0cfe74e885b7b2ff841706a89dec2b1 SHA-256: c7c73738407ba77e31a165ef4f5ceb82e410319924abe2c593ec2952c5f1a7e2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links. These links point to external PDF files hosted on the domain 'easckaolp.myhome.cx', suggesting a link farm or a distribution point for further malicious content. The document body was unreadable, but the heuristic firings strongly indicate a malicious intent related to link manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/9843845840/The-Beatles-in-Comics-by-Gaet-39-s.pdf
    • http://easckaolp.myhome.cx/3840840848848845/The-Beatles-Lyrics-The-Songs-of-Lennon-McCartney-Harrison-and-Starr-by-The-Beatles.pdf
    • http://easckaolp.myhome.cx/4840848843846841/Read-the-Beatles-Classic-and-New-Writings-on-the-Beatles-Their-Legacy-and-Why-They-Still-Matter-by-June-Skinner-Sawyers.pdf
    • http://easckaolp.myhome.cx/1841845842842846847/The-Beatles-Lyrics-The-Stories-Behind-the-Music-Including-the-Handwritten-Drafts-of-More-Than-100-Classic-Beatles-Songs-by-Hunter-Davies.pdf
    • http://easckaolp.myhome.cx/1840849844840840848/Focus-On-100-Most-Popular-Fictional-Adoptees-Jessica-Jones-Iron-Man-Princess-Leia-Quicksilver-comics-Havok-comics-Jon-Snow-character-Uhtred-Krueger-Rogue-comics-Hellboy-etc-by-Wikipedia-contributors.pdf
    • http://easckaolp.myhome.cx/2846845840845848/The-Beatles-Complete-Chord-Songbook-by-The-Beatles.pdf
    • http://easckaolp.myhome.cx/6845843845844/Donald-Duck-Comics-Donald-Duck-Comics-by-Carl-Barks-Donald-Duck-Comics-by-Don-Rosa-the-Life-and-Times-of-Scrooge-McDuck-by-Source-Wikipedia.pdf
    • http://easckaolp.myhome.cx/6844846841841842/Secret-Comics-Japan-Underground-Comics-Now-by-Hyoe-Narita.pdf
    • http://easckaolp.myhome.cx/1840845844847849849/Comics-Squad-2-Lunch-Comics-Squad-2-by-Matthew-Holm.pdf
    • http://easckaolp.myhome.cx/7845847841841845/Toronto-Comics-Anthology-Toronto-Comics-1-by-Steven-Andrews.pdf
    • http://easckaolp.myhome.cx/9842842841842843/Archie-1000-Page-Comics-Digest-by-Archie-Comics.pdf
    • http://easckaolp.myhome.cx/7845847841845842/Toronto-Comics-Volume-3-Toronto-Comics-3-by-Steven-Andrews.pdf
    • http://easckaolp.myhome.cx/6846841842840844/Articles-on-French-Comics-Writers-Including-Ren-Goscinny-Enki-Bilal-Jacques-Tardi-Alejandro-Jodorowsky-Sylvain-Chomet-Joann-Sfar-Jacques-Martin-Comics-Fran-OIS-Bourgeon-Emmanuel-Larcenet-David-Beauchard-Lewis-Trondheim-by-Hephaestus-Books.pdf
    • http://easckaolp.myhome.cx/9840845842840/The-Best-of-Archie-Comics-Volume-2-by-Archie-Comics.pdf
    • http://easckaolp.myhome.cx/1841844841846844847/The-Beatles-de-biografie-by-Bob-Spitz.pdf
    • http://easckaolp.myhome.cx/4848846844843844/Yellow-Submarine-by-The-Beatles.pdf
    • http://easckaolp.myhome.cx/3849845847840849/Who-Were-the-Beatles-by-Geoff-Edgers.pdf
    • http://easckaolp.myhome.cx/4849848844845842/The-Unseen-Beatles-by-Robert-Whitaker.pdf
    • http://easckaolp.myhome.cx/3847843846842843/The-Beatles-Anthology-by-George-Harrison.pdf
    • http://easckaolp.myhome.cx/4849848843849841/Visualising-The-Beatles-by-John-Pring.pdf
    • http://easckaolp.myhome.cx