Malicious PDF — malware analysis report

Static analysis result for SHA-256 014e417e51857839…

MALICIOUS

PDF

19.6 KB Created: 2019-05-07 04:35:08 +01:00 Authoring application: mPDF 5.7
MD5: f82c7b5a5f493311285d43bccfbfcd80 SHA-1: 7c2bbfe770a4f779e286bd390f8be29025b7d703 SHA-256: 014e417e51857839eb738ddda2e375e424758ad33f5a7f20d9205f95d26009be
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, identified as a link farm. While the ML classifier flagged the PDF as malicious, the primary heuristic indicates a SEO link farm strategy. The embedded URLs themselves are not directly malicious but are used to populate the document body and potentially drive traffic or manipulate search results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a05a09a02a05a08/AngelFall-Epic-A-Tale-in-Rhymed-Epic-Verse-by-Nathan-Spinaze.pdf
    • http://muicuiu.dumb1.com/2a07a05a01a00a02/Lugalbanda-The-Boy-Who-Got-Caught-Up-in-a-War-An-Epic-Tale-From-Ancient-Iraq-by-Kathy-Henderson.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a09a01a09/Evangeline-A-Tale-of-Acadie-epic-poem---1848-by-Henry-Wadsworth-Longfellow.pdf
    • http://muicuiu.dumb1.com/2a05a06a01a07a05/The-Snakehead-An-Epic-Tale-of-the-Chinatown-Underworld-and-the-American-Dream-by-Patrick-Radden-Keefe.pdf
    • http://muicuiu.dumb1.com/8a02a01a04a07a03/Man-the-story-of-his-advent-life-and-development-in-the-earth-world-and-his-continued-life-and-progression-in-the-spirit-world-with-a-description-allegory-of-his-principal-aids-and-counsellors-told-in-epic-verse-by-Edwy-Wells-Foster.pdf
    • http://muicuiu.dumb1.com/8a04a03a05a08/The-Ancient-Irish-Epic-Tale-Tain-Bo-Cualnge-the-Cualnge-Cattle-Raid-by-Unknown.pdf
    • http://muicuiu.dumb1.com/2a02a07a00a07a01/Epic-Zero-by-R-L-Ullman.pdf
    • http://muicuiu.dumb1.com/2a04a01a09a04/The-Underground-Abductor-An-Abolitionist-Tale-about-Harriet-Tubman-Nathan-Hale-s-Hazardous-Tales-5-by-Nathan-Hale.pdf
    • http://muicuiu.dumb1.com/4a01a06a03a07a03/The-Epic-Crush-of-Genie-Lo-The-Epic-Crush-of-Genie-Lo-1-by-F-C-Yee.pdf
    • http://muicuiu.dumb1.com/9a09a06a01a04a07/The-Epic-of-Gilgamesh-by-Anonymous.pdf
    • http://muicuiu.dumb1.com/8a06a02a05a08a03/Epic-of-Gilgamesh-PB-by-Anonymous.pdf
    • http://muicuiu.dumb1.com/3a00a07a07a05a06/Epic-Fantasy-0-9b-by-Will-Weisser.pdf
    • http://muicuiu.dumb1.com/3a02a06a05a01a06/The-Epic-of-Gilgamesh-by-Anonymous.pdf
    • http://muicuiu.dumb1.com/2a02a05a03a07a07/The-Epic-of-Gilgamesh-by-Anonymous.pdf
    • http://muicuiu.dumb1.com/3a03a07a00a03a03/Epic-Fail-by-Claire-LaZebnik.pdf
    • http://muicuiu.dumb1.com/4a00a05a06a09a05/Resurrection-Zombie-Epic-by-Tim-Curran.pdf
    • http://muicuiu.dumb1.com/4a07a07a00a03a02/Edda-Epic-3-by-Conor-Kostick.pdf
    • http://muicuiu.dumb1.com/7a09a01a05a00a09/Bismarck-The-Epic-Sea-Chase-by-Jim-Crossley.pdf
    • http://muicuiu.dumb1.com/2a09a00a08/Desperately-Seeking-Epic-by-B-N-Toler.pdf
    • http://muicuiu.dumb1.com/1a07a06a01a09a05/Edda-Epic-3-by-Conor-Kostick.pdf