Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce2bc14ab1a4ca0d…

MALICIOUS

PDF

18.1 KB Created: 2020-03-16 04:51:07 +00:00 Authoring application: mPDF 5.7
MD5: bca51080203ed7209a0967742f9aeb76 SHA-1: 10b8ffd212b7b24fb2923b4f209237b47f1010f8 SHA-256: ce2bc14ab1a4ca0d47fd09b274cfbdf0a3806f15ac1a2e5e93b60f30c3b19386
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by a machine learning classifier and contains a large number of embedded links, indicating a link farm or redirection scheme. The primary heuristic identified a "PDF_SEO_LINK_FARM" with 24 numeric slug SEO PDF links, all pointing to the dominant host "easckaolp.myhome.cx". This suggests the document is designed to lure users to external, potentially malicious, content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/2846849846848843/Seduced-by-a-Wolf-by-McKenna-Chase.pdf
    • http://easckaolp.myhome.cx/2840846841849844/Panthers-Pleasure-Impulse-1-by-Zara-Chase.pdf
    • http://easckaolp.myhome.cx/2844844849840849/Sweet-Memories-of-Pain-amp-the-Future-of-Pleasure-by-TammyJo-Eckhart.pdf
    • http://easckaolp.myhome.cx/1847844846840841/Pleasure-Island-Pleasure-Cruise-3-by-Mandy-M-Roth.pdf
    • http://easckaolp.myhome.cx/7847846847849848/Eden-s-Pleasure-House-of-Pleasure-0-5-by-Kate-Pearce.pdf
    • http://easckaolp.myhome.cx/3840848848849845/The-Official-Chase-N-Yur-Face-Cookbook-Tasty-Recipes-Fun-Facts-To-Start-Your-Food-Adventure-by-Chase-Bailey.pdf
    • http://easckaolp.myhome.cx/3848845845846847/Giving-Chase-Chase-Brothers-1-by-Lauren-Dane.pdf
    • http://easckaolp.myhome.cx/1842843843840849/Making-Chase-Chase-Brothers-4-by-Lauren-Dane.pdf
    • http://easckaolp.myhome.cx/8845846849849849/Male-Multiple-Orgasm-The-Ultimate-Guide-on-Becoming-a-Multi-Orgasmic-Man-Gain-Ultimate-Control---Get-More-Pleasure---Give-More-Pleasure-by-B-Foyer.pdf
    • http://easckaolp.myhome.cx/7845840841844/For-His-Pleasure-For-His-Pleasure-1-by-Kelly-Favor.pdf
    • http://easckaolp.myhome.cx/3843847840841847/The-Chase-Volume-3-The-Chase-3-by-Jessica-Wood.pdf
    • http://easckaolp.myhome.cx/3843846847848845/The-Chase-Volume-2-The-Chase-2-by-Jessica-Wood.pdf
    • http://easckaolp.myhome.cx/8843844843849/Magnus-Chase-and-the-Hammer-of-Thor-Magnus-Chase-and-the-Gods-of-Asgard-2-by-Rick-Riordan.pdf
    • http://easckaolp.myhome.cx/2844844842844844/Chase-Tinker-and-the-House-of-Secrets-Chase-Tinker-2-by-Malia-Ann-Haberman.pdf
    • http://easckaolp.myhome.cx/7840846843848847/Sweet-Masterpiece-Samantha-Sweet-1-by-Connie-Shelton.pdf
    • http://easckaolp.myhome.cx/2849843844842842/Sophie-s-Sweet-Seduction-Sweet-Temptations-3-by-L-J-Anderson.pdf
    • http://easckaolp.myhome.cx/2841846845844847/Sweet-Memories-Love-So-Sweet-1-by-Steena-Holmes.pdf
    • http://easckaolp.myhome.cx/2847844845842842/Revenge-is-Sweet-Kali-Sweet-1-by-Misty-Evans.pdf
    • http://easckaolp.myhome.cx/1840849848843/The-Sweet-Spot-Sweet-on-a-Cowboy-1-by-Laura-Drake.pdf
    • http://easckaolp.myhome.cx/4844844843841843/Pleasure-Cruise-Pleasure-Cruise-1-by-Michelle-M-Pillow.pdf