Malicious PDF — malware analysis report

Static analysis result for SHA-256 690b6f63e0923716…

MALICIOUS

PDF

24.3 KB Created: 2020-03-13 19:53:00 +00:00 Authoring application: mPDF 5.7
MD5: 07114ff95291b7f27f387875460d744d SHA-1: d853739e5892719891343c7c8d5217d4d48a2d96 SHA-256: 690b6f63e0923716002df78f23e71d853d4dc602df4cd2d00cfae5158368bc30
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, indicative of a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of numerous external links suggests a potential for malicious redirection or content delivery, possibly related to SEO manipulation or phishing lures.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/1cd6cd7cd6cd8cd4/Icewind-Dale-Trilogy-Forgotten-Realms-Icewind-Dale-1-3-Legend-of-Drizzt-4-6-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd7cd1cd1/Streams-of-Silver-Forgotten-Realms-Icewind-Dale-2-Legend-of-Drizzt-5-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd7cd0cd7/The-Dark-Elf-Trilogy-Collector-s-Edition-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-Ghost-King-Forgotten-Realms-Transitions-3-Legend-of-Drizzt-19-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd6cd9cd0/Charon-s-Claw-Forgotten-Realms-Neverwinter-3-Legend-of-Drizzt-22-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd0cd2cd4/Starless-Night-Forgotten-Realms-Legacy-of-the-Drow-2-Legend-of-Drizzt-8-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd7cd4cd0cd1/The-Spine-of-the-World-Forgotten-Realms-Paths-of-Darkness-2-Legend-of-Drizzt-12-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd8cd6cd1cd6/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd6cd7cd3cd0cd4/Aussi-loin-qu-une-me-ait-pu-fuir-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd3cd6cd7/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd9cd7cd9cd7/The-Hunter-s-Blades-Collector-s-Edition-Forgotten-Realms-Hunter-s-Blades-1-3-Legend-of-Drizzt-14-16-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd2cd9cd6cd9/Sojourn-Dark-Elf-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd0cd0cd4cd9/The-Companions-The-Sundering-1-The-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd6cd8cd7/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd6cd0/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd7cd1cd9/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd2cd6cd4cd9/Siege-of-Darkness-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd2cd6cd6cd3cd1/Road-of-the-Patriarch-Forgotten-Realms-The-Sellswords-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd2cd2cd4cd4/Canticle-Forgotten-Realms-The-Cleric-Quintet-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd6cd2cd7cd0cd6/The-Chaos-Curse-Forgotten-Realms-The-Cleric-Quintet-5-by-R-A-Salvatore.pdf