Malicious PDF — malware analysis report

Static analysis result for SHA-256 f952457ae6f019df…

MALICIOUS

PDF

26.1 KB Created: 2020-03-18 16:41:36 +00:00 Authoring application: mPDF 5.7
MD5: b96e41d743f480b3596d77fabfede4c1 SHA-1: 8c0fafad9d12e3b2d3e39c8d592c8e83e4f24e61 SHA-256: f952457ae6f019df5daa0c635345872ad51140070c92f2e4338c939b9fa3af8e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a domain with a suspicious structure and numerous links, likely to host further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/2aa4aa2aa8aa4aa5/Alfred-Hitchcock-And-The-3-Investigators-Mystery-Of-The-Flaming-Footprints-Mystery-Of-The-Coughing-Dragon-Mystery-Of-The-Singing-Serpent-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/8aa9aa6aa4aa5aa5/The-Mystery-of-the-Singing-Serpent-Alfred-Hitchcock-and-The-Three-Investigators-17-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/2aa4aa5aa2aa0aa8/The-Mystery-of-the-Singing-Serpent-Alfred-Hitchcock-and-The-Three-Investigators-17-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/4aa9aa6aa4aa9aa5/The-Mystery-of-the-Coughing-Dragon-Alfred-Hitchcock-and-The-Three-Investigators-14-by-Nick-West.pdf
    • http://eascasas.myhome.cx/8aa9aa6aa4aa5aa9/The-Mystery-of-the-Magic-Circle-Alfred-Hitchcock-and-The-Three-Investigators-27-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/1aa3aa8aa2aa4aa7/The-Mystery-of-the-Screaming-Clock-Alfred-Hitchcock-and-The-Three-Investigators-9-by-Robert-Arthur.pdf
    • http://eascasas.myhome.cx/1aa8aa4aa4aa2aa9/The-Mystery-of-the-Stuttering-Parrot-Alfred-Hitchcock-and-The-Three-Investigators-2-by-Robert-Arthur.pdf
    • http://eascasas.myhome.cx/2aa3aa7aa3aa6aa4/The-Mystery-of-the-Green-Ghost-Alfred-Hitchcock-and-The-Three-Investigators-4-by-Robert-Arthur.pdf
    • http://eascasas.myhome.cx/2aa4aa5aa0aa6aa1/The-Mystery-of-the-Shrinking-House-Alfred-Hitchcock-and-The-Three-Investigators-18-by-William-Arden.pdf
    • http://eascasas.myhome.cx/2aa7aa2aa1aa2/Alfred-Hitchcock-s-Home-Sweet-Homicide-Stories-from-Alfred-Hitchcock-s-Mystery-Magazine-by-Alfred-Hitchcock.pdf
    • http://eascasas.myhome.cx/8aa9aa6aa4aa6aa3/The-Mystery-of-the-Wandering-Caveman-The-Three-Investigators-34-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/8aa9aa6aa4aa6aa6/The-Mystery-of-the-Cranky-Collector-The-Three-Investigators-43-by-M-V-Carey.pdf
    • http://eascasas.myhome.cx/3aa1aa7aa6aa6aa0/The-Secret-of-the-Crooked-Cat-Alfred-Hitchcock-and-The-Three-Investigators-13-by-William-Arden.pdf
    • http://eascasas.myhome.cx/7aa5aa3aa6aa4/The-Secret-of-Terror-Castle-Alfred-Hitchcock-and-The-Three-Investigators-1-by-Robert-Arthur.pdf
    • http://eascasas.myhome.cx/2aa4aa5aa2aa0aa3/The-Secret-of-Phantom-Lake-Alfred-Hitchcock-and-The-Three-Investigators-19-by-William-Arden.pdf
    • http://eascasas.myhome.cx/3aa9aa1aa3aa2aa6/Footprints-in-the-Sand-Wedding-Cake-Mystery-3-by-Mary-Jane-Clark.pdf
    • http://eascasas.myhome.cx/4aa8aa2aa5aa1aa5/The-Flaming-Luau-of-Death-A-Madeline-Bean-Catering-Mystery-7-by-Jerrilyn-Farmer.pdf
    • http://eascasas.myhome.cx/1aa6aa3aa6aa5aa0/Dial-H-for-Hitchcock-A-Cece-Caruso-Mystery-5-by-Susan-Kandel.pdf
    • http://eascasas.myhome.cx/6aa8aa5aa5aa1aa3/The-Summer-Fete-Mystery-The-Jess-Mystery-Series-Book-4-by-Nina-Levison.pdf
    • http://eascasas.myhome.cx/1aa7aa9aa4aa1aa8/No-Cooperation-from-the-Cat-A-Mystery-Trixie-Dolan-amp-Evangeline-Sinclair-Mystery-7-by-Marian-Babson.pdf
    • http://eascasas.myhome.cx/4aa9