Malicious PDF — malware analysis report

Static analysis result for SHA-256 c844825069f110c5…

MALICIOUS

PDF

19.3 KB Created: 2020-02-13 18:47:51 +00:00 Authoring application: mPDF 5.7
MD5: 55122a9ae695478537683578d72b6e3f SHA-1: d39d5d1680273d7b655b0d16201c1ccb01c0b388 SHA-256: c844825069f110c551d9c5ca8acf700fe4107855842bcabde1bb2125acaa2164
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly flagged this PDF as malicious. The embedded URLs likely serve to direct users to malicious content or phishing sites, constituting a form of social engineering.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/6cd9cd9cd5cd9cd6/Are-Racists-Crazy-How-Prejudice-Racism-and-Antisemitism-Became-Markers-of-Insanity-by-Sander-L-Gilman.pdf
    • http://ujcsiniio.myhome.cx/9cd6cd6cd0cd4/Racism-without-Racists-Color-Blind-Racism-and-the-Persistence-of-Racial-Inequality-in-the-United-States-by-Eduardo-Bonilla-Silva.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd3cd1cd5cd0/Hysteria-Beyond-Freud-by-Sander-L-Gilman.pdf
    • http://ujcsiniio.myhome.cx/1cd2cd1cd2cd4cd1/Insanity-Insanity-1-by-Cameron-Jace.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd7cd3cd8cd6/Driving-Her-Crazy-Crazy-Love-1-by-Kira-Archer.pdf
    • http://ujcsiniio.myhome.cx/5cd1cd8cd9cd9cd3/A-History-of-Antisemitism-in-Canada-by-Ira-Robinson.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd2cd3cd9cd6/Pride-and-Prejudice-and-Secrets-Pride-and-Prejudice-Variation-Sequel-The-Poison-Series-Book-2-by-Bella-Breen.pdf
    • http://ujcsiniio.myhome.cx/1cd2cd5cd4cd1cd0/Globalising-Hatred-The-New-Antisemitism-by-Denis-MacShane.pdf
    • http://ujcsiniio.myhome.cx/1cd3cd2cd2cd7cd2/A-Convenient-Hatred-The-History-of-Antisemitism-by-Phyllis-Goldstein.pdf
    • http://ujcsiniio.myhome.cx/4cd1cd5cd7cd9cd9/On-Antisemitism-Solidarity-and-the-Struggle-for-Justice-by-Jewish-Voice-for-Peace.pdf
    • http://ujcsiniio.myhome.cx/9cd8cd7cd3cd0cd5/Herland-Original-by-Charlotte-Perkins-Gilman-by-Charlotte-Perkins-Gilman.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd7cd1cd8cd2/What-Looks-Like-Crazy-Crazy-1-by-Charlotte-Hughes.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd5cd0cd5cd4cd5/Erotisches-Quartett-by-Lia-Sander.pdf
    • http://ujcsiniio.myhome.cx/8cd8cd0cd1cd2cd4/Kaviar-zum-Fr-hst-ck-by-Lia-Sander.pdf
    • http://ujcsiniio.myhome.cx/8cd0cd5cd3cd9/zersetzt-by-Lena-Sander.pdf
    • http://ujcsiniio.myhome.cx/5cd0cd7cd3cd5cd6/Nazi-Germany-Canadian-Responses-Confronting-Antisemitism-in-the-Shadow-of-War-by-L-Ruth-Klein.pdf
    • http://ujcsiniio.myhome.cx/6cd9cd4cd0cd6cd1/The-Aesthetics-of-Hate-Far-Right-Intellectuals-Antisemitism-and-Gender-in-1930s-France-by-Sandrine-Sanos.pdf
    • http://ujcsiniio.myhome.cx/6cd9cd9cd5cd1cd7/Mating-Markers---Book-1-by-Teeta.pdf
    • http://ujcsiniio.myhome.cx/6cd9cd9cd5cd5cd1/Sketching-With-Markers-by-Thomas-C-Wang.pdf
    • http://ujcsiniio.myhome.cx/6cd9cd9cd6cd0cd2/Mating-Markers---Book-4-by-Teeta.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd2cd3cd9cd6/Pride-and-Prejudice-and-Secrets-Pride-and-Prejudice-