Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e0bcb78e22a6084…

MALICIOUS

PDF

20.4 KB Created: 2020-03-20 03:39:49 +00:00 Authoring application: mPDF 5.7
MD5: f1c610903b356ff60fdd9439f13791d6 SHA-1: 07b155e7476652d6fa97842bf0651a57534a58f8 SHA-256: 1e0bcb78e22a60848efcf9f5f8586dd2afb87e33a9af175eb8041373db9ed2b0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'ujcsiniio.myhome.cx'. This pattern is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/2cd0cd9cd2/It-Ended-Badly-Thirteen-of-the-Worst-Breakups-in-History-by-Jennifer-Wright.pdf
    • http://ujcsiniio.myhome.cx/2cd6cd5cd5cd9cd3/Thirteen-Days-in-September-The-Dramatic-Story-of-the-Struggle-for-Peace-in-the-Middle-East-by-Lawrence-Wright.pdf
    • http://ujcsiniio.myhome.cx/3cd9cd5cd6cd2cd9/The-Worst-Children-s-Jobs-in-History-by-Tony-Robinson.pdf
    • http://ujcsiniio.myhome.cx/9cd1cd3cd8/Killing-the-SS-The-Hunt-for-the-Worst-War-Criminals-in-History-by-Bill-O-39-Reilly.pdf
    • http://ujcsiniio.myhome.cx/5cd3cd8cd4cd8cd8/Wrapped-In-White-Thirteen-Tales-of-Spectres-Ghosts-and-Spirits-Wrapped-2-by-Jennifer-L-Greene.pdf
    • http://ujcsiniio.myhome.cx/5cd5cd4cd0cd6cd6/Scenes-of-Parisian-Life-Vol-6-History-of-the-Thirteen-Ferragus-La-Duchesse-de-Langeais-by-Honor-de-Balzac.pdf
    • http://ujcsiniio.myhome.cx/1cd2cd1cd6cd2cd2/The-Thirteen-Secrets-Thirteen-Treasures-3-by-Michelle-Harrison.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd5cd8cd5cd1/The-Great-Big-Book-of-Horrible-Things-The-Definitive-Chronicle-of-History-s-100-Worst-Atrocities-by-Matthew-White.pdf
    • http://ujcsiniio.myhome.cx/4cd8cd3cd8cd8cd8/Winds-of-Fire-The-Arcadia-Falls-Chronicles-5-by-Jennifer-Malone-Wright.pdf
    • http://ujcsiniio.myhome.cx/8cd4cd0cd2cd0cd4/Sound-of-Sirens-The-Arcadia-Falls-Chronicles-9-by-Jennifer-Malone-Wright.pdf
    • http://ujcsiniio.myhome.cx/4cd1cd2cd6cd8cd0/Thirteen-The-Last-Thirteen-1-by-James-Phelan.pdf
    • http://ujcsiniio.myhome.cx/9cd2cd0cd3cd7/A-Short-History-of-Progress-by-Ronald-Wright.pdf
    • http://ujcsiniio.myhome.cx/4cd0cd1cd5cd1cd2/History-of-the-world-the-last-five-hundred-years-by-Esmond-Wright.pdf
    • http://ujcsiniio.myhome.cx/3cd6cd1cd3cd9cd1/A-Short-History-of-the-Shadow-Poems-by-Charles-Wright.pdf
    • http://ujcsiniio.myhome.cx/9cd2cd5cd2cd3cd3/The-Strange-History-of-Buckingham-Palace-Patterns-of-People-by-Patricia-Wright.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd4cd9cd8cd0/The-History-of-Lucy-s-Love-Life-in-Ten-and-a-Half-Chapters-by-Deborah-Wright.pdf
    • http://ujcsiniio.myhome.cx/1cd8cd5cd5cd9cd4/The-Buffalo-Creek-Disaster-How-the-Survivors-of-One-of-the-Worst-Disasters-in-Coal-Mining-History-Brought-Suit-Against-the-Coal-Company--And-Won-by-Gerald-M-Stern.pdf
    • http://ujcsiniio.myhome.cx/3cd7cd4cd9cd2cd2/The-Worst-Witch-Saves-The-Day-Worst-Witch-Book-5-by-Jill-Murphy.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd6cd2cd5cd7/The-Worst-Witch-to-the-Rescue-Worst-Witch-6-by-Jill-Murphy.pdf
    • http://ujcsiniio.myhome.cx/3cd2cd3cd7cd1cd0/Behaving-Badly-by-Isabel-Wolff.pdf
    • http://ujcsiniio.myhome.cx/5cd5cd4cd0cd6cd6/Scenes-of-Par