Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5da980355a6d0c1…

MALICIOUS

PDF

25.0 KB Created: 2020-03-13 19:57:16 +00:00 Authoring application: mPDF 5.7
MD5: dec38d3da6860e54bec88e52783f8f70 SHA-1: 6032e0c7cf0332c46f7c133b5dbe4f6a65e3c2d1 SHA-256: b5da980355a6d0c1733e8a772ac44b70d81a1921f486b9cdcfa0dac95f58d038
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'ujcsiniio.myhome.cx'. This behavior is indicative of a link farm or a distribution point for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/6cd6cd7cd3cd0cd4/Aussi-loin-qu-une-me-ait-pu-fuir-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd7cd4cd0cd1/The-Spine-of-the-World-Forgotten-Realms-Paths-of-Darkness-2-Legend-of-Drizzt-12-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd8cd6cd1cd6/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd6cd9cd0/Charon-s-Claw-Forgotten-Realms-Neverwinter-3-Legend-of-Drizzt-22-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-Ghost-King-Forgotten-Realms-Transitions-3-Legend-of-Drizzt-19-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd0cd2cd4/Starless-Night-Forgotten-Realms-Legacy-of-the-Drow-2-Legend-of-Drizzt-8-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd7cd1cd1/Streams-of-Silver-Forgotten-Realms-Icewind-Dale-2-Legend-of-Drizzt-5-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd0cd3cd7cd5/Servant-of-the-Shard-Forgotten-Realms-Paths-of-Darkness-3-The-Sellswords-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd3cd6cd7/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd9cd7cd9cd7/The-Hunter-s-Blades-Collector-s-Edition-Forgotten-Realms-Hunter-s-Blades-1-3-Legend-of-Drizzt-14-16-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd7cd0cd7/The-Dark-Elf-Trilogy-Collector-s-Edition-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd6cd7cd6cd8cd4/Icewind-Dale-Trilogy-Forgotten-Realms-Icewind-Dale-1-3-Legend-of-Drizzt-4-6-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd2cd6cd4cd9/Siege-of-Darkness-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd2cd9cd6cd9/Sojourn-Dark-Elf-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd6cd8cd7/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd6cd0/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd0cd0cd4cd9/The-Companions-The-Sundering-1-The-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd7cd1cd9/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd2cd2cd4cd4/Canticle-Forgotten-Realms-The-Cleric-Quintet-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd2cd6cd6cd3cd1/Road-of-the-Patriarch-Forgotten-Realms-The-Sellswords-3-by-R-A-Salvatore.pdf