Malicious PDF — malware analysis report

Static analysis result for SHA-256 5127472f716b93da…

MALICIOUS

PDF

22.5 KB Created: 2020-03-15 09:44:56 +00:00 Authoring application: mPDF 5.7
MD5: e31eb327505d74c4af2db7c890fa23f1 SHA-1: a995f37a3b172a2ce7c633f8000a17b4b46485bf SHA-256: 5127472f716b93da9158968d0b5f9393c8e87d44ba2836c8bdeedc61736c7635
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files hosted on the domain 'ujcsiniio.myhome.cx'. This pattern is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/1cd1cd2cd1cd2cd1cd9/The-Inspiring-Journey-of-a-Hero-Learnings-from-the-Life-of-O-P-Munjal-by-Priya-Kumar.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd1cd4cd3cd9/Dream-Dare-Deliver-The-Inspirational-Journey-of-Subhasish-Chakraborty-and-the-making-of-DTDC-by-Priya-Kumar.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd1cd4cd3cd3/SHOBHA-PRIYA-by-Praveen-Kumar.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd1cd4cd9cd4/Ava-Book-One-in-the-Priya-Series-A-Priya-Novel-Volume-1-by-Ashley-Barron.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd2cd4cd8cd1cd5/Earth-to-Centauri-The-First-Journey-Captain-Anara---Antariksh-1-by-Kumar-L-.pdf
    • http://ujcsiniio.myhome.cx/4cd3cd6cd5cd7cd9/Life-Makeovers-52-Practical-amp-Inspiring-Ways-to-Improve-Your-Life-One-Week-at-a-Time-by-Cheryl-Richardson.pdf
    • http://ujcsiniio.myhome.cx/7cd0cd3cd1cd4/The-Hero-s-Journey-Joseph-Campbell-on-His-Life-amp-Work-by-Joseph-Campbell.pdf
    • http://ujcsiniio.myhome.cx/9cd3cd5cd5cd7/Life-Of-Love-by-Santonu-Kumar-Dhar.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd9cd9cd2cd4/Life-Of-Love-by-Santonu-Kumar-Dhar.pdf
    • http://ujcsiniio.myhome.cx/3cd0cd4cd0cd4cd6/Champions-15-Inspiring-Comeback-Stories-from-Sports-and-Life-by-George-Castle.pdf
    • http://ujcsiniio.myhome.cx/9cd8cd7cd3cd0cd1/Single-Man-The-Life-And-Times-Of-Nitish-Kumar-Of-Bihar-by-Sankarshan-Thakur.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd9cd3cd6/Soldier-and-Spice---An-Army-Wife-s-Life-by-Aditi-Mathur-Kumar.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd2cd0cd7cd2/Love-Has-a-Price-Tag-Inspiring-Stories-That-Will-Open-Your-Heart-to-Life-s-Little-Miracles-by-Elisabeth-Elliot.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd9cd0cd6/Who-Ordered-This-Truckload-of-Dung-Inspiring-Stories-for-Welcoming-Life-s-Difficulties-by-Ajahn-Brahm.pdf
    • http://ujcsiniio.myhome.cx/7cd4cd4cd8cd3cd5/Hero-s-Journey-Sweet-Pepper-Fire-Brigade-Mystery-1-5-by-J-J-Cook.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd7cd3cd6cd9/Fat-Forty-and-Fired-One-man-s-frank-funny-and-inspiring-account-of-losing-his-job-and-finding-his-life-by-Nigel-Marsh.pdf
    • http://ujcsiniio.myhome.cx/4cd1cd2cd7cd3cd9/Living-the-Hero-s-Journey-Exploring-Your-Role-in-the-Action-Adventure-of-a-Lifetime-by-Will-Craig.pdf
    • http://ujcsiniio.myhome.cx/9cd8cd7cd1cd3cd0/Dilip-Kumar-The-Substance-and-the-Shadow-by-Dilip-Kumar.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd5cd3cd3cd2/Superhero-Therapy-A-Hero-s-Journey-through-Acceptance-and-Commitment-Therapy-by-Janina-Scarlet.pdf
    • http://ujcsiniio.myhome.cx/4cd6cd6cd0cd5cd8/Raise-Your-Hand-if-You-Love-Horses-Pat-Parelli-s-Journey-from-Zero-to-Hero-by-Pat-Parelli.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd9cd9cd2cd4/Life-Of-Lov