Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd3358186ed9d392…

MALICIOUS

PDF

14.6 KB Created: 2020-03-18 21:12:51 +00:00 Authoring application: mPDF 5.7
MD5: f700cfafa1d95b123b5ddcddf5cbdf11 SHA-1: 1e9ebb3189ec8280c8acb9131293221aef573457 SHA-256: fd3358186ed9d3927ae25b396041500e89292b98263dca9371c50deff44b3c41
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDFs on the domain easckaolp.myhome.cx. This is indicative of a link farm or a lure to download further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://easckaolp.myhome.cx/9842842849848846/Geile-Fickspiele-mit-der-G-rtnerin-by-Verena-Mannsfeld.pdf
    • http://easckaolp.myhome.cx/1841844844842841841/Janine---Gefickt-von-drei-M-nnern-by-Verena-Mannsfeld.pdf
    • http://easckaolp.myhome.cx/1840843847849841841/Nasse-Fickspiele-GayMale-by-Amy-Hinkle.pdf
    • http://easckaolp.myhome.cx/8849849849846840/Die-geile-Elfe-by-Ino-Oe.pdf
    • http://easckaolp.myhome.cx/1840841842846845843/Saying-Goodbye-to-Verena-by-Ivy-Turow.pdf
    • http://easckaolp.myhome.cx/1840841842846845847/Balik-Kampung-by-Verena-Tay.pdf
    • http://easckaolp.myhome.cx/1841847846841845846/Heidi-und-der-geile-Gro-vater-by-Gero-Last.pdf
    • http://easckaolp.myhome.cx/1840841842848844841/Balik-Kampung-2B-Contemplations-by-Verena-Tay.pdf
    • http://easckaolp.myhome.cx/9848848847844844/Geile-Meile-Sammelband-by-Frank-G-hre.pdf
    • http://easckaolp.myhome.cx/9844842841844844/Paar-treibt-geile-Spiele-by-SteviaMaus.pdf
    • http://easckaolp.myhome.cx/1841849845848848846/Das-Gl-ck-in-wei-en-N-chten-by-Verena-Rabe.pdf
    • http://easckaolp.myhome.cx/1841842848848844844/Mein-Nachbar-der-Million-r-by-Verena-Bergmeier.pdf
    • http://easckaolp.myhome.cx/1840840840845844842/Susi-will-ein-Krampus-sein-by-Verena-J-rgo.pdf
    • http://easckaolp.myhome.cx/1840842848849849845/Linus-P-und-ein-Aufsatz-mit-Folgen-by-Verena-K-Bauer.pdf
    • http://easckaolp.myhome.cx/9849844844846840/Geile-Stuten-auf-harten-Kn-ppeln-by-Stefan-Obermann.pdf
    • http://easckaolp.myhome.cx/1841842844849845846/Eine-geile-Pr-fung-Entjungfern-by-Lisa-Lust.pdf
    • http://easckaolp.myhome.cx/9841841848842840/Die-anal-geile-W-chterin-auf-der-Bank-by-Daniele-Arian.pdf
    • http://easckaolp.myhome.cx/9847846848848842/Junge-Kerle-v-geln-geile-Grannys-by-Zoran-Zecke.pdf
    • http://easckaolp.myhome.cx/1841845847846843843/Kundenbindung-im-Multi-Channel-Management-von-Banken-by-Verena-Schabbach.pdf
    • http://easckaolp.myhome.cx/9844847848847842/Sunnyboy-und-reife-Frucht-Geile-Erotik-Story-by-Bernadette-Binkowski.pdf