Malicious PDF — malware analysis report

Static analysis result for SHA-256 d69c5db48c25d260…

MALICIOUS

PDF

24.3 KB Created: 2020-03-13 19:57:53 +00:00 Authoring application: mPDF 5.7
MD5: 5d15758559b9d3493d78ea13a812f80b SHA-1: b84fa6ef5f75735ddd1bf11eabe53214e1c8f44f SHA-256: d69c5db48c25d260de7ed73c166b91403e39202ec93b06673f5e459c04822722
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, characteristic of a link farm or SEO poisoning attack. The primary heuristic indicates a mass of external PDF links, with the first identified URL being http://ujcsiniio.myhome.cx/8cd2cd0cd2cd4/Starless-Night-Forgotten-Realms-Legacy-of-the-Drow-2-Legend-of-Drizzt-8-by-R-A-Salvatore.pdf. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/8cd2cd0cd2cd4/Starless-Night-Forgotten-Realms-Legacy-of-the-Drow-2-Legend-of-Drizzt-8-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd3cd6cd7/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd4cd1cd7/Legacy-of-the-Drow-Legacy-of-the-Drow-1-4-Legend-of-Drizzt-7-10-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd2cd6cd4cd9/Siege-of-Darkness-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-Ghost-King-Forgotten-Realms-Transitions-3-Legend-of-Drizzt-19-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd6cd9cd0/Charon-s-Claw-Forgotten-Realms-Neverwinter-3-Legend-of-Drizzt-22-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/7cd7cd4cd0cd1/The-Spine-of-the-World-Forgotten-Realms-Paths-of-Darkness-2-Legend-of-Drizzt-12-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd8cd6cd1cd6/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd2cd7cd1cd1/Streams-of-Silver-Forgotten-Realms-Icewind-Dale-2-Legend-of-Drizzt-5-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd6cd7cd3cd0cd4/Aussi-loin-qu-une-me-ait-pu-fuir-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd3cd7cd0cd7/The-Dark-Elf-Trilogy-Collector-s-Edition-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd9cd7cd9cd7/The-Hunter-s-Blades-Collector-s-Edition-Forgotten-Realms-Hunter-s-Blades-1-3-Legend-of-Drizzt-14-16-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd6cd7cd6cd8cd4/Icewind-Dale-Trilogy-Forgotten-Realms-Icewind-Dale-1-3-Legend-of-Drizzt-4-6-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd1cd2cd9cd6cd9/Sojourn-Dark-Elf-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd6cd8cd7/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd6cd0/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd2cd0cd0cd4cd9/The-Companions-The-Sundering-1-The-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd4cd3cd7cd1cd9/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/3cd2cd6cd6cd3cd1/Road-of-the-Patriarch-Forgotten-Realms-The-Sellswords-3-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/6cd2cd2cd4cd4/Canticle-Forgotten-Realms-The-Cleric-Quintet-1-by-R-A-Salvatore.pdf
    • http://ujcsiniio.myhome.cx/2cd9cd2cd2cd8cd6/The-Ghost-King-Forgotten-Realms-Transitions-3-Legend-of-Drizzt-1