Malicious PDF — malware analysis report

Static analysis result for SHA-256 e062914c60af123f…

MALICIOUS

PDF

16.8 KB Created: 2020-02-11 22:08:56 +00:00 Authoring application: mPDF 5.7
MD5: 0ed02dba3239b39f5bd73b38528da2b4 SHA-1: 87ec0e75c1acfccfb8ff9384a9f375885aeff1e8 SHA-256: e062914c60af123f00a68a66ab143ba8eb3ac0c14671a0f4d8e5e05c599f913e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'ujcsiniio.myhome.cx'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/2cd1cd7cd2cd8cd9/Wife-For-a-Week-Bennett-Family-1-by-Kelly-Hunter.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd3cd9cd8cd5cd4/The-Holy-Week-Devotional-Holy-Week---It-s-Not-Just-Another-Week-by-Leisa-Wilkins.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd3cd0cd5cd5cd3/The-Great-Week-An-Explanation-of-the-Liturgy-of-Holy-Week-by-Aemiliana-L-hr.pdf
    • http://ujcsiniio.myhome.cx/9cd5cd2cd3cd6cd7/Spelling-Demons-Week-by-Week-by-Elizabeth-Hagner.pdf
    • http://ujcsiniio.myhome.cx/1cd8cd3cd2cd8/Our-Family-Meeting-Book-Fun-and-Easy-Ways-to-Manage-Time-Build-Communication-and-Share-Responsibility-Week-by-Week-by-Elaine-Hightower.pdf
    • http://ujcsiniio.myhome.cx/3cd9cd6cd4cd6cd6/Your-Pregnancy-Week-by-Week-by-Glade-B-Curtis.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd2cd5cd4/Small-Moments-Stories-by-Nancy-Huddleston-Packer.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd0cd5cd8cd5cd3/Education-Conflict-and-Reconciliation-International-Perspectives-Edited-by-Fiona-Leach-and-Mirad-Dunne-by-Fiona-Leach.pdf
    • http://ujcsiniio.myhome.cx/1cd5cd1cd5/Four-Week-Fianc-Four-Week-Fianc-1-by-Helen-Cooper.pdf
    • http://ujcsiniio.myhome.cx/4cd6cd5cd9cd4cd2/The-Strange-Death-of-Fiona-Griffiths-Fiona-Griffiths-3-by-Harry-Bingham.pdf
    • http://ujcsiniio.myhome.cx/3cd1cd0cd1cd8cd6/The-Birthday-Cake-Book-Fiona-Cairns-by-Fiona-Cairns.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd8cd8cd5cd2/Naked-and-Sexual-Fiona-Thrust-1-by-Fiona-Thrust.pdf
    • http://ujcsiniio.myhome.cx/5cd4cd5cd8cd8cd7/Harry-Boland---A-Man-Divided-By-Andrew-Brasier-and-John-Kelly-by-John-Kelly.pdf
    • http://ujcsiniio.myhome.cx/4cd1cd2cd3cd0cd6/One-Week-by-Nikki-Van-De-Car.pdf
    • http://ujcsiniio.myhome.cx/3cd5cd5cd4cd3cd7/One-Week-by-K-Mason.pdf
    • http://ujcsiniio.myhome.cx/5cd8cd4cd9cd9cd2/Wordpress-in-a-week-Or-less-by-Zak-Cagaros.pdf
    • http://ujcsiniio.myhome.cx/6cd0cd2cd5cd8/A-Week-to-Forever-by-Stephanie-Zen.pdf
    • http://ujcsiniio.myhome.cx/7cd5cd2cd2cd0cd6/Ravaged-His-For-A-Week-2-by-Em-Brown.pdf
    • http://ujcsiniio.myhome.cx/1cd7cd8cd5cd3cd4/A-Week-At-The-Beach-by-Virginia-Jewel.pdf
    • http://ujcsiniio.myhome.cx/2cd8cd7cd3cd0cd0/One-Week-in-December-by-Holly-Chamberlin.pdf