Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3a52e98e8570793…

MALICIOUS

PDF

23.5 KB Created: 2020-03-20 16:19:39 +00:00 Authoring application: mPDF 5.7
MD5: 83e0abf4f951636bd718f5f44a9646c2 SHA-1: 04b43739ad91a251be38c8ea1119996af30e6c62 SHA-256: d3a52e98e857079355dbccae01f797184fccc222d4bf432b7b20d49cf0b75818
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious websites. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 28 links, suggesting a coordinated effort to distribute malicious content. The ML classifier's high score further supports the malicious nature of the file. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/3aa8aa4aa7aa5/The-Woman-Who-Married-a-Cloud-The-Collected-Short-Stories-by-Jonathan-Carroll.pdf
    • http://eascasas.myhome.cx/8aa7aa6aa9aa0/The-Collected-Stories-of-Lewis-Carroll-Alice-in-Wonderland-Through-the-Looking-Glass-Phantasmagoria-by-Lewis-Carroll.pdf
    • http://eascasas.myhome.cx/5aa7aa7aa9aa6aa8/Fugue-A-Collection-of-Contemporary-Short-Stories-by-Lucy-Carroll.pdf
    • http://eascasas.myhome.cx/3aa8aa7aa7aa7aa0/The-Collected-Short-Stories-by-Jean-Rhys.pdf
    • http://eascasas.myhome.cx/7aa8aa8aa0aa6aa6/Collected-Short-Stories-by-Bertolt-Brecht.pdf
    • http://eascasas.myhome.cx/3aa2aa8aa4aa9aa5/The-Short-Happy-Life-of-the-Brown-Oxford-and-Other-Classic-Stories-The-Collected-Stories-of-Philip-K-Dick-Vol-1-Vol-1-by-Philip-K-Dick.pdf
    • http://eascasas.myhome.cx/3aa5aa2aa5aa5aa6/The-New-Woman-s-Hour-Book-Of-Short-Stories-by-Di-Speirs.pdf
    • http://eascasas.myhome.cx/3aa2aa5aa3aa6aa7/You-Can-t-Keep-a-Good-Woman-Down-Short-Stories-by-Alice-Walker.pdf
    • http://eascasas.myhome.cx/2aa2aa1aa6aa3aa3/A-Day-in-the-Life-of-a-Smiling-Woman-Complete-Short-Stories-by-Margaret-Drabble.pdf
    • http://eascasas.myhome.cx/3aa1aa3aa2aa7aa5/Short-Stories-for-Early-Readers-17-Short-Stories-Included-Tall-Tales-Kids-Story-Bundle-Childrens-ebooks-Short-Story-Series-Diaries-of-Simple-Reading-by-Betty-J-Byers.pdf
    • http://eascasas.myhome.cx/6aa6aa8aa2aa8aa5/Lewis-Carroll-Box-Set-Alice-Adventures-in-Wonderland-and-Through-the-Looking-Glass-Including-the-Short-Film-the-Delivery-by-Lewis-Carroll.pdf
    • http://eascasas.myhome.cx/9aa9aa3aa7aa0aa8/Great-American-Short-Stories-vol-1-The-Birthmark-The-Threefold-Destiny-An-Old-Woman-s-Tale-by-Nathaniel-Hawthorne.pdf
    • http://eascasas.myhome.cx/2aa8aa7aa3aa0aa2/The-Collected-Short-Stories-of-Louis-L-Amour-The-Adventure-Stories-by-Louis-L-39-Amour.pdf
    • http://eascasas.myhome.cx/8aa1aa7aa2aa5aa3/Sherlock-Holmes-The-Adventures-of-Sherlock-Holmes-Short-Stories-Collected-Illustrated-and-Annotated-by-Arthur-Conan-Doyle.pdf
    • http://eascasas.myhome.cx/3aa6aa2aa0aa3aa8/The-Sin-Cloud-B-C-2-by-Jonathan-R-Walton.pdf
    • http://eascasas.myhome.cx/1aa0aa5aa0aa2aa7/The-Collected-Stories-of-Philip-K-Dick-1-The-Short-Happy-Life-of-the-Brown-Oxford-by-Philip-K-Dick.pdf
    • http://eascasas.myhome.cx/3aa1aa3aa2aa8aa2/Short-Elementary-Level-Stories-Bundle-5-3-Short-Stories-in-1-Ebook-Books-about-love-signing-baby-animals-school-planets-family-Perfect-for-kids-under-10-learning-to-read-by-Betty-J-Byers.pdf
    • http://eascasas.myhome.cx/1aa3aa0aa2aa3aa6/The-Ghost-in-Love-by-Jonathan-Carroll.pdf
    • http://eascasas.myhome.cx/3aa0aa7aa4aa1aa4/Voice-Of-Our-Shadow-by-Jonathan-Carroll.pdf
    • http://eascasas.myhome.cx/4aa0aa2aa8aa8aa2/Bones-of-the-Moon-by-Jonathan-Carroll.pdf
    • http://eascasas.myhome.cx/3aa5aa2aa5aa5aa6/The-New-Woman-s-Hour-Book-Of-Short-Stories-by-Di-Spei