Malicious PDF — malware analysis report

Static analysis result for SHA-256 58779d8d3d7600be…

MALICIOUS

PDF

21.2 KB Created: 2020-03-18 17:57:09 +00:00 Authoring application: mPDF 5.7
MD5: d8b1b981f45671a3c50f2b4334524ec9 SHA-1: 97959bf85aee985b6e7d370dc2a18b05a363b91d SHA-256: 58779d8d3d7600be76b753f7f59e8e125374d48a93fb944e81b6cef8bb45a3ba
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed it contains a large number of embedded links pointing to external PDF files hosted on the domain 'ujcsiniio.myhome.cx'. This suggests a link farm or redirection scheme designed to lead users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/8cd9cd4cd6cd9cd3/Das-Haus-der-Hebamme-Roman-by-Tanja-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd8cd3/Tanjas-Welt-Weitere-60-launige-Geschichten---so-richtig-aus-dem-Leben-by-Tanja-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd9cd5/Tanjas-Welt-Band-1-60-launige-Kurzgeschichten---so-richtig-aus-dem-Leben-by-Tanja-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd9cd8/Tanjas-Welt-Band-5-weitere-60-launige-Geschichten---so-richtig-aus-dem-Leben-by-Tanja-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd7cd3cd2/Tanjas-Welt-Band-4-weitere-60-launige-Geschichten---so-richtig-au-sdem-Leben-by-Tanja-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd7cd7cd8cd9cd9/Das-Haus-der-blauen-Schmetterlinge-Roman-by-Sarah-Benedict.pdf
    • http://ujcsiniio.myhome.cx/9cd4cd4cd6cd8cd3/Das-Haus-der-gl-cklichen-Alten-Roman-by-Valter-Hugo-M-e.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd8cd6/Rainer-Wekwerth---Die-Abenteuer-des-Ritter-Rumpel-Band-1---Drachenfeuer-by-Rainer-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/9cd6cd9cd9cd7cd3/Jenseits-Der-Zeit-en-Zum-Problem-Der-Zeit-in-Christoph-Ransmayrs-Roman-Die-Letzte-Welt-by-Tanja-Stramiello.pdf
    • http://ujcsiniio.myhome.cx/8cd6cd1cd2cd0cd3/Ein-Mann-f-rs-Haus-Zwei-Schwestern-auf-der-Suche-nach-einem-Mann-f-r-ihre-Mutter---Roman-by-Nina-Stibbe.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd2cd4cd5cd9/1000-Fragen-An-Die-Hebamme-by-Birgit-Laue.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd2cd5cd4cd9/Lesbische-Spiele-mit-meiner-Hebamme-by-Laura-M-nzel.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd0cd1cd6cd2/Von-Windeln-verweht-Aus-dem-Leben-einer-Hebamme-by-Esther-Howoldt.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd7cd3cd7/Pheromon-Reihe-in-3-B-nden-by-Rainer-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd2cd6cd3cd5/Bei-Anruf-Baby-Aus-dem-Alltag-einer-au-ergew-hnlichen-Hebamme-by-Ursula-Walch.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd2cd6cd7cd9/Hom-opathie-f-r-den-Hebammenalltag-Das-Kompendium-f-r-jede-hom-opathisch-arbeitende-Hebamme-by-Ingeborg-Stadelmann.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd2cd6/Blink-of-Time---Jagt-Sarah-Layken-by-Rainer-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/1cd4cd1cd9cd9cd5/Bottoms-by-Tanja-Kirschner.pdf
    • http://ujcsiniio.myhome.cx/9cd6cd3cd8cd3cd1/Dem-Leibe-Abgelesen-by-Tanja-van-Hoorn.pdf
    • http://ujcsiniio.myhome.cx/9cd3cd0cd3cd6cd1/Der-silberne-Fl-gel-by-Tanja-Bern.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd7cd7cd8cd9cd9/Das-Haus-der-blauen