Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d6c28d6a845360…

MALICIOUS

PDF

20.7 KB Created: 2020-03-19 02:37:42 +00:00 Authoring application: mPDF 5.7
MD5: 168bdc76f32141887c2cc3816c0f17f0 SHA-1: 9f34dedac642303554b477064d723d497b4210f7 SHA-256: d9d6c28d6a8453604eaffb64725f0b2715f30a3f644b240e6b03714cde212ca1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain 'ujcsiniio.myhome.cx'. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/1cd0cd3cd2cd4cd6cd8/Sensational-Sex-The-Ultimate-Guide-to-Sex-and-Passion-by-Linda-Sonntag.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd2cd6cd3cd1/Giant-Book-Of-Questions-And-Answers-by-Linda-Sonntag.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd2cd5cd0cd9/Sex-Mix-A-Split-Page-Mix-and-Match-Book-for-Couples-with-Fun-Forepley-and-Hot-Positions-by-Linda-Sonntag.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd9cd8cd2cd5cd7/30-Days-to-Diamond-The-Ultimate-League-of-Legends-Guide-to-Climbing-Ranked-The-Ultimate-League-of-Legends-Guide-to-Climbing-the-Ranked-Ladder-Book-1-by-St-Petr.pdf
    • http://ujcsiniio.myhome.cx/5cd7cd9cd1cd7cd3/Ultimate-Handbook-Guide-to-Bucharest-Romania-Travel-Guide-by-Hye-Ducharme.pdf
    • http://ujcsiniio.myhome.cx/2cd5cd3cd4cd4cd5/Passion-Fruit-Farming-A-Step-by-Step-Guide-to-Growing-Passion-Fruit-for-Profit-by-Christopher-Makomere.pdf
    • http://ujcsiniio.myhome.cx/1cd9cd0cd5cd2cd8/Cracked-Hearts-The-Story-of-Ultimate-Betrayal-and-Love-by-Linda-Masemore-Pirrung.pdf
    • http://ujcsiniio.myhome.cx/9cd7cd0cd1cd0/Cryptocurrency-For-Dummies-The-Ultimate-Guide-to-Investing-and-Trading-in-Cryptocurrency-for-Beginners-The-Easiest-Guide-to-Understand-Blockchain-Bitcoin-ICO-and-others-by-Jones-Richblood.pdf
    • http://ujcsiniio.myhome.cx/8cd2cd7cd2cd9cd1/The-Ultimate-Guide-to-Permaculture-by-Faires.pdf
    • http://ujcsiniio.myhome.cx/8cd0cd7cd0cd9cd7/The-ultimate-guide-to-texting-girls-by-Artisan.pdf
    • http://ujcsiniio.myhome.cx/5cd0cd2cd3cd3/The-Ultimate-Ps3-tm-Repair-Guide-by-Andrew-Wright.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd4cd8cd8cd3cd2/How-To-Drive-The-Ultimate-Guide-from-the-Man-Who-Was-the-Stig-by-Ben-Collins.pdf
    • http://ujcsiniio.myhome.cx/5cd7cd7cd3cd7cd1/The-Ultimate-Guide-to-Anal-Sex-for-Women-by-Tristan-Taormino.pdf
    • http://ujcsiniio.myhome.cx/3cd9cd9cd9cd0cd2/The-Ultimate-Guide-to-Green-Parenting-by-Zion-Lights.pdf
    • http://ujcsiniio.myhome.cx/7cd5cd8cd4cd2/Vampire-Academy-The-Ultimate-Guide-by-Michelle-Rowen.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd3cd5cd5cd9cd9/Weight-Training-for-Golf-The-Ultimate-Guide-by-Kai-Fusser.pdf
    • http://ujcsiniio.myhome.cx/8cd0cd0cd0cd3cd7/The-Gun-Owner-s-Bible-The-Ultimate-Guide-by-James-Darnell.pdf
    • http://ujcsiniio.myhome.cx/3cd5cd5cd2cd3cd3/The-Ultimate-Teen-Book-Guide-by-Daniel-Hahn.pdf
    • http://ujcsiniio.myhome.cx/7cd2cd5cd1cd0cd3/The-Ultimate-Guide-to-Umrah-by-Abu-Muneer-Ismail-Davids.pdf
    • http://ujcsiniio.myhome.cx/6cd3cd7cd3cd1/Night-World-The-Ultimate-Fan-Guide-by-Annette-Pollert.pdf
    • http://ujcsiniio.myhome.cx/2cd5cd3cd4cd4cd5/Passion-Fruit-Farming-A-Step-by-Step-Guide-to-Growing-Pas