Malicious PDF — malware analysis report

Static analysis result for SHA-256 44253807b6d79f68…

MALICIOUS

PDF

25.0 KB Created: 2020-03-13 19:56:49 +00:00 Authoring application: mPDF 5.7
MD5: 889a279ff1bc2a8899d77396f3842ca3 SHA-1: f5d0c79c0fe460fb20fbc3863f2d8ccb80c9cbe0 SHA-256: 44253807b6d79f685d191d0a867b49d603cda2356e452b68bfc52e57a05a3e50
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'ujcsiniio.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/4cd8cd6cd1cd6/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd7cd4cd0cd1/The-Spine-of-the-World-Forgotten-Realms-Paths-of-Darkness-2-Legend-of-Drizzt-12-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd6cd7cd3cd0cd4/Aussi-loin-qu-une-me-ait-pu-fuir-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd6cd9cd0/Charon-s-Claw-Forgotten-Realms-Neverwinter-3-Legend-of-Drizzt-22-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-Ghost-King-Forgotten-Realms-Transitions-3-Legend-of-Drizzt-19-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd0cd2cd4/Starless-Night-Forgotten-Realms-Legacy-of-the-Drow-2-Legend-of-Drizzt-8-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd7cd1cd1/Streams-of-Silver-Forgotten-Realms-Icewind-Dale-2-Legend-of-Drizzt-5-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd0cd3cd7cd5/Servant-of-the-Shard-Forgotten-Realms-Paths-of-Darkness-3-The-Sellswords-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd3cd6cd7/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd7cd0cd7/The-Dark-Elf-Trilogy-Collector-s-Edition-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd9cd7cd9cd7/The-Hunter-s-Blades-Collector-s-Edition-Forgotten-Realms-Hunter-s-Blades-1-3-Legend-of-Drizzt-14-16-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd6cd7cd6cd8cd4/Icewind-Dale-Trilogy-Forgotten-Realms-Icewind-Dale-1-3-Legend-of-Drizzt-4-6-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd2cd6cd4cd9/Siege-of-Darkness-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd6cd0/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd2cd9cd6cd9/Sojourn-Dark-Elf-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd6cd8cd7/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd0cd0cd4cd9/The-Companions-The-Sundering-1-The-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd7cd1cd9/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd2cd6cd6cd3cd1/Road-of-the-Patriarch-Forgotten-Realms-The-Sellswords-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd2cd2cd4cd4/Canticle-Forgotten-Realms-The-Cleric-Quintet-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-G