Malicious PDF — malware analysis report

Static analysis result for SHA-256 503f4a4b760606dc…

MALICIOUS

PDF

17.5 KB Created: 2020-03-14 02:02:06 +00:00 Authoring application: mPDF 5.7
MD5: aebb607c81f9290730e6e794579a364f SHA-1: 435bed1b7ce80ffa4eea6e75f4e5736eaa5725ff SHA-256: 503f4a4b760606dc442e947d5cd3ab16c57d8a32c3e6038b499daa4448d6fa25
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves directing users to a link farm hosted on 'weisncio.myhome.cx'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1621626622625620623/YuYu-Hakusho-Volume-13-Full-Power-One-Last-Time-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628626629/Yu-Yu-Hakusho-Volume-18-The-Demon-Plane-Unification-Tournament-Yu-Yu-Hakusho-18-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628626628/Yu-Yu-Hakusho-Volume-15-Showdown-at-the-Eleventh-Hour-Yu-Yu-Hakusho-15-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627625629/Yu-Yu-Hakusho-Volume-6-The-Dark-Tournament-Yu-Yu-Hakusho-6-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628626623/Yu-Yu-Hakusho-Volume-14-A-Bloody-Past-Yu-Yu-Hakusho-14-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628620628/Yu-Yu-Hakusho-Volume-8-Open-Your-Eyes-Yu-Yu-Hakusho-8-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/8624628627628/Weed-Volume-2-by-Yoshihiro-Takahashi.pdf
    • http://weisncio.myhome.cx/7622623629621620/The-Leap-Launching-Your-Full-Time-Career-in-Our-Part-Time-Economy-by-Robert-Dickie.pdf
    • http://weisncio.myhome.cx/5628629628621629/Hunter-x-Hunter-Vol-33-Hunter-x-Hunter-33-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627626621/Hunter-x-Hunter-Vol-11-Hunter-x-Hunter-11-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628626625/Hunter-x-Hunter-Vol-20-Hunter-x-Hunter-20-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628627620/Hunter-x-Hunter-Vol-23-Hunter-x-Hunter-23-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628621621/Hunter-x-Hunter-Vol-26-Hunter-x-Hunter-26-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628620625/Hunter-x-Hunter-Vol-19-Hunter-x-Hunter-19-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628621624/Hunter-x-Hunter-Vol-28-Hunter-x-Hunter-28-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627626620/Hunter-x-Hunter-Vol-17-Hunter-x-Hunter-17-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/1623628624624627/The-Sources-of-Social-Power-Volume-1-a-History-of-Power-from-the-Beginning-to-Ad-1760-by-Michael-Mann.pdf
    • http://weisncio.myhome.cx/3629621623628622/Silence-The-Power-of-Quiet-in-a-World-Full-of-Noise-by-Thich-Nhat-Hanh.pdf
    • http://weisncio.myhome.cx/6620622624621627/Full-Metal-Panic-Volume-6-Full-Metal-Panic-6-by-Shouji-Gatou.pdf
    • http://weisncio.myhome.cx/6620622624622620/Full-Metal-Panic-Volume-8-Full-Metal-Panic-8-by-Shouji-Gatou.pdf