Malicious PDF — malware analysis report

Static analysis result for SHA-256 d7fb49b56c3553c8…

MALICIOUS

PDF

17.9 KB Created: 2020-03-16 04:46:45 +00:00 Authoring application: mPDF 5.7
MD5: 8b652a9f751e59e61f9f06f244a3e947 SHA-1: e86cd338435a3ac8300ff4d82e199f1723e82a7d SHA-256: d7fb49b56c3553c8d42f8c073669904e9a5e854f6123ea18fcfabd4bec01b2af
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain easckaolp.myhome.cx. This heuristic firing indicates a link farm, likely intended to drive traffic or host malicious content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/8846841849846846/The-Blasphemy-in-the-Canopic-Jar-amp-More-Tales-Of-The-Cthulhu-Mythos-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/3840847843846848/Shoggoth-Apocalypse-amp-More-Tales-Of-The-Cthulhu-Mythos-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/4840847847844845/Tales-of-the-Cthulhu-Mythos-by-H-P-Lovecraft.pdf
    • http://easckaolp.myhome.cx/4848846842846840/The-Dark-Boatman-Tales-of-Horror-and-the-Cthulhu-Mythos-by-John-Glasby.pdf
    • http://easckaolp.myhome.cx/9849840841846844/The-Cthulhu-Mythos-by-August-Derleth.pdf
    • http://easckaolp.myhome.cx/2843841849845846/Cthulhu-The-Mythos-and-Kindred-Horrors-by-Robert-E-Howard.pdf
    • http://easckaolp.myhome.cx/9849840841846849/Sherlock-Holmes-Cthulhu-Mythos-Adventures-by-Ralph-E-Vaughan.pdf
    • http://easckaolp.myhome.cx/3848846848846848/Urban-Temples-of-Cthulhu---Modern-Mythos-Anthology-by-Khurt-Khave.pdf
    • http://easckaolp.myhome.cx/9849840843842843/High-Seas-Cthulhu-Swashbuckling-Adventure-Meets-the-Mythos-by-William-Jones.pdf
    • http://easckaolp.myhome.cx/3845844848849845/In-the-Belly-of-the-Beast-and-Other-Tales-of-Cthulhu-Wars-A-Cthulhu-Wars-Novel-by-Ben-Monroe.pdf
    • http://easckaolp.myhome.cx/8846841848848848/Canopic-Jars-Tales-of-Mummies-and-Mummification-by-Gregory-L-Norris.pdf
    • http://easckaolp.myhome.cx/4841840847847845/Nameless-Cults-The-Complete-Cthulhu-Mythos-Fiction-of-Robert-E-Howard-by-Robert-E-Howard.pdf
    • http://easckaolp.myhome.cx/7841842849840846/Techno-Goth-Cthulhu-by-Mark-Anthony-Crittenden.pdf
    • http://easckaolp.myhome.cx/5840847849842/Best-Little-Witch-House-in-Arkham-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/1842842841849848/Hideous-Faces-Beautiful-Skulls-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/2848840849846843/Hideous-Faces-Beautiful-Skulls-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/1842847842848845/Escape-of-the-50-Foot-Prison-Bitch-by-Mark-McLaughlin.pdf
    • http://easckaolp.myhome.cx/9847848842849/Black-Wings-of-Cthulhu-2-Eighteen-Tales-of-Lovecraftian-Horror-by-S-T-Joshi.pdf
    • http://easckaolp.myhome.cx/9849840843842846/Return-Of-The-Deep-Ones-And-Other-Mythos-Tales-by-Brian-Lumley.pdf
    • http://easckaolp.myhome.cx/8846842840842843/Canopic-Equipment-in-the-Petrie-Museum-by-Vivien-Raisman.pdf