Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a9bab2ee3d1fe59…

MALICIOUS

PDF

23.6 KB Created: 2020-03-18 22:30:12 +00:00 Authoring application: mPDF 5.7
MD5: ad1a8ed63baad52338dcba72a38e17d3 SHA-1: aac68375b060b7444717909e2a1313882b821ff8 SHA-256: 8a9bab2ee3d1fe59b15ccfedb57098f63549ca3c782c9ceff8eb668efe7ef26f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'ujcsiniio.myhome.cx'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/9cd6cd5cd2cd3cd7/Perfektion-Key-to-see-10-Wege-das-Leben-zu-leben-by-Mira-M-hlenhof.pdf
    • http://ujcsiniio.myhome.cx/8cd6cd7cd9cd8cd9/So-Leben-Sie-Die-Sieben-Wege-Zur-Effektivit-t-Das-Bew-hrte-Covey-Erfolgskonzept-In-Der-Praxis-by-Stephen-R-Covey.pdf
    • http://ujcsiniio.myhome.cx/9cd1cd2cd5cd3cd5/Leben-Lieben-Leiten---Heute-beginnt-dein-bestes-Leben---by-Brian-Houston.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd6cd2cd5cd3cd8/Ich-will-leben-Gedichte-die-das-Leben-schrieb-by-Christina-M-lling.pdf
    • http://ujcsiniio.myhome.cx/9cd1cd7cd7cd7cd6/Die-Leben-des-Billy-Milligan-die-komplizierte-schockierende-und-wahre-Lebensgeschichte-eines-Mannes-in-dessen-Gehirn-24-Pers-nlichkeiten-nebeneinander-leben---eine-davon-ist-ein-Verbrecher-by-Daniel-Keyes.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd4cd0cd6cd1cd9/Leben-trotz-Krebs---eine-Farbe-mehr-Interviews-zu-einem-gelingenden-Leben-nach-Krebs-by-Elmar-Reuter.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd3cd0cd6cd5cd9/Gelassenheit-lernen-WIE-SIE-GELASSENHEIT-LERNEN-RGER-UND-SORGEN-LOSLASSEN-UND-ENTSPANNT-UND-GL-CKLICH-LEBEN-Die-10-Wege-zu-Gelassenheit-und-innerer-Ruhe-Gelassenheit-lernen-schenkt-Freiheit-Gelassenheit-lernen-in-der-Praxis-mit-Schritt-f-r-Sch-by-Mariana-Seiler.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd6cd4cd4cd2/Leben-In-Der-Schattenwelt-by-J-rg-Alt.pdf
    • http://ujcsiniio.myhome.cx/9cd7cd9cd7cd1cd9/YOU-amp-ME---Ein-neues-halbes-Leben-You-amp-Me-3-by-Any-Cherubim.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd2cd7cd4cd2cd0/Geschichten-aus-dem-Leben-und-zum-Nachdenken-by-P-M-Rindermann.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd8cd4cd6cd5/Der-Weg-zur-Quelle-Leben-und-Tod-in-Pal-stina-by-Ben-Ehrenreich.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd6cd2cd4cd2cd2/Der-Tag-an-dem-mir-das-Leben-schrieb-by-Nancy-Salchow.pdf
    • http://ujcsiniio.myhome.cx/9cd1cd2cd3cd7cd9/Heute-will-ich-leben-by-Nora-Price.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd1cd2cd9cd5/Das-Leben-retten-by-Marc-Bekoff.pdf
    • http://ujcsiniio.myhome.cx/9cd4cd0cd8cd4cd5/wie-das-Leben-so-spielt-by-G-nter-Gruber.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd7cd3cd6cd0cd5/Leben-Beate-by-Anna-Thur.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd6cd0cd1cd5cd5/Ein-Leben-in-23-Tagen-by-Alva-Sokopp.pdf
    • http://ujcsiniio.myhome.cx/7cd1cd5cd7cd0cd4/Wir-leben-in-Australien-by-Annie-Langlois.pdf
    • http://ujcsiniio.myhome.cx/9cd2cd1cd3cd1cd2/Fragen-an-das-Leben-by-Rolf-Dobelli.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd5cd7cd0cd3cd1/Der-Tag-an-dem-ich-lernte-zu-leben-Roman-by-Laurent-Gounelle.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd4cd0cd6cd1cd9/Leben-trotz-Krebs---eine-Farbe-mehr-Interv