Malicious PDF — malware analysis report

Static analysis result for SHA-256 beb1d7f01d29df22…

MALICIOUS

PDF

20.1 KB Created: 2020-03-18 22:00:20 +00:00 Authoring application: mPDF 5.7
MD5: a6d3351ab3b556f2f0dec7b1796d7503 SHA-1: 2d4744a07ee18332529337553895767eaeb66569 SHA-256: beb1d7f01d29df2289d35927b5ad79eb7aeda3bb218999a7b119129f7a429be7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links to external PDF files, indicative of a link farm or a phishing lure. The primary attack pattern involves directing users to these external resources, which are likely malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/3cd1cd2cd8cd2/The-Library-Ghost-of-Tanglewood-Inn-A-Jaya-Jones-Treasure-Hunt-Mystery-5-5-by-Gigi-Pandian.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd6cd9cd0cd3/The-Alchemist-s-Illusion-by-Gigi-Pandian.pdf
    • http://ujcsiniio.myhome.cx/4cd1cd8cd2cd4cd8/Ghost-Hunt-Vol-1-Ghost-Hunt-1-by-Shiho-Inada.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd5cd6cd4cd5/Ghost-Hunt-Vol-2-Ghost-Hunt-2-by-Shiho-Inada.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd2cd2cd1cd3/Treasure-of-Egypt-Humorous-Mystery-Book-1---Treasure-of-the-Ancients-by-Barbara-Ivie-Green.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd7cd2cd3cd7cd8/Merrydale-Treasure-Hunt-by-Linda-M-Jennings.pdf
    • http://ujcsiniio.myhome.cx/8cd4cd6cd2cd4cd3/Metal-A-Treasure-Hunt-by-Java-Davis.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd0cd3cd6cd7/Pattern-tastic-Treasure-Hunt-by-Hvass-amp-Hannibal.pdf
    • http://ujcsiniio.myhome.cx/1cd5cd1cd5cd5cd1/The-Christmas-Tree-Treasure-Hunt-by-Joan-Campbell.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd5cd2cd6cd0/Secret-Garden-An-Inky-Treasure-Hunt-and-Colouring-Book-by-Johanna-Basford.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd9cd0cd8cd9cd3/The-Ghost-Library-by-David-Melling.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd3cd7cd1cd1/The-Complete-Works-of-Nathaniel-Hawthorne-Novels-Short-Stories-Poetry-Essays-Letters-and-Memoirs-Illustrated-Edition-The-Scarlet-Letter-with-its-Romance-Tanglewood-Tales-Birthmark-Ghost-by-Nathaniel-Hawthorne.pdf
    • http://ujcsiniio.myhome.cx/2cd7cd1cd7cd7cd4/The-Monuments-Men-Allied-Heroes-Nazi-Thieves-And-The-Greatest-Treasure-Hunt-In-History-by-Robert-M-Edsel.pdf
    • http://ujcsiniio.myhome.cx/3cd8cd1cd9cd3cd5/We-re-Going-on-a-Ghost-Hunt-by-Marcia-K-Vaughan.pdf
    • http://ujcsiniio.myhome.cx/3cd8cd2cd2cd8cd6/The-Library-of-Souls-Ghost-Talker-Files-1-by-Richard-Denney.pdf
    • http://ujcsiniio.myhome.cx/2cd6cd6cd7cd4cd0/The-Library-of-Lost-Books-by-Darius-Jones.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd6cd8cd0cd3/Ghost-Hunt-Chilling-Tales-of-the-Search-for-the-Unknown-by-Jason-Hawes.pdf
    • http://ujcsiniio.myhome.cx/1cd7cd9cd0cd9cd3/Due-or-Die-Library-Lover-s-Mystery-2-by-Jenn-McKinlay.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd6cd0cd2cd8cd5/TKKG-Mystery-of-the-Mayan-Treasure-by-Tivola-Electronic-Publishing.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd8cd4cd4cd5/The-Spook-in-the-Stacks-Lighthouse-Library-Mystery-4-by-Eva-Gates.pdf
    • http://ujcsiniio.myhome.cx/1cd5cd1cd5cd5cd1/The-Ch