Malicious PDF — malware analysis report

Static analysis result for SHA-256 78fa143a8655770e…

MALICIOUS

PDF

21.1 KB Created: 2020-03-18 17:44:08 +00:00 Authoring application: mPDF 5.7
MD5: 9518f257535c1e8c1059d734a1ab2036 SHA-1: 3c4f85f1a79483242ece663f28e100e31c2da235 SHA-256: 78fa143a8655770e8226086322068c56ebce341ae1e29e47920731e8e40af21f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on the ujcsiniio.myhome.cx domain. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm designed to manipulate search engine results or distribute malicious content via these external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/1cd0cd8cd5cd5cd5cd1/Van-Richmond-Naar-Reid-Bronnen-En-Ontwikkeling-Van-Taakgerichte-Hulpverlening-In-Het-Maatschappelijk-Werk-by-L-J-Jagt.pdf
    • http://ujcsiniio.myhome.cx/6cd0cd0cd1cd7cd3/NLP-in-ontwikkeling-een-open-manifest-by-Rudy-Vandamme.pdf
    • http://ujcsiniio.myhome.cx/6cd0cd3cd1cd5cd1/Psychosociale-gespreksvoering-Observatief-luisteren-in-de-hulpverlening-by-Markus-van-Alphen.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd8cd5cd5cd5cd2/The-Sleeping-Princess-of-Nulland-by-Aaron-Jagt.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd4cd6cd2cd6/Blink-of-Time---Jagt-Sarah-Layken-by-Rainer-Wekwerth.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd8cd5cd3cd1cd2/The-Escape-The-Adventures-of-Three-Huguenot-Children-Fleeing-Persecution-by-A-Van-Der-Jagt.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd5cd9cd3cd4/Blankow-of-Het-verlangen-naar-Heimat-by-Pauline-de-Bok.pdf
    • http://ujcsiniio.myhome.cx/1cd6cd6cd7cd4cd1/Duivelsmuziek-op-de-fiets-van-Memphis-naar-New-Orleans-by-Leendert-van-der-Valk.pdf
    • http://ujcsiniio.myhome.cx/5cd7cd1cd9cd4cd8/Donuteconomie-in-zeven-stappen-naar-een-economie-voor-de-21e-eeuw-by-Kate-Raworth.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd2cd2cd5cd9cd6/Met-een-der-stoomers-van-de-Maatschappij-Nederland-naar-Genua-De-Aarde-en-haar-Volken-1908-by-J-Craandijk.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd4cd1cd4cd1cd1/Wiskunde-En-Besliskunde-25-Jaar-Later-Van-Leer-Van-Het-Programmeren-Van-Stochastische-En-Deterministische-Economische-Beslissingsprocessen-Naar-Toege-by-Jacobus-Kriens.pdf
    • http://ujcsiniio.myhome.cx/5cd1cd9cd3cd6cd5/De-kleine-verschillen-die-het-leven-uitmaken-Een-historische-studie-naar-joodse-sociaal-democraten-en-socialistisch-zionisten-in-Nederland-by-Evelien-Gans.pdf
    • http://ujcsiniio.myhome.cx/6cd4cd0cd0cd0/The-Year-of-Fog-by-Michelle-Richmond.pdf
    • http://ujcsiniio.myhome.cx/1cd4cd5cd1cd7/Day-the-Indians-Came-by-Robert-Richmond.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd1cd1cd0cd3/Castle-Richmond-by-Anthony-Trollope.pdf
    • http://ujcsiniio.myhome.cx/3cd7cd3cd9cd8cd9/Christmas-Journeys-by-Emma-Richmond.pdf
    • http://ujcsiniio.myhome.cx/4cd5cd5cd1cd0cd5/Spring-for-Susannah-by-Catherine-Richmond.pdf
    • http://ujcsiniio.myhome.cx/8cd5cd1cd8cd0/Konin-A-Quest-by-Theo-Richmond.pdf
    • http://ujcsiniio.myhome.cx/1cd9cd1cd6cd7cd6/Greek-Lyrics-by-Richmond-Lattimore.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd6cd4cd0cd2cd5/Werk-in-uitvoering-by-Richard-Bachman.pdf