Malicious PDF — malware analysis report

Static analysis result for SHA-256 06b47f75b408c1d5…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 05:22:53 +01:00 Authoring application: mPDF 5.7
MD5: 8b9de8c97370d76f792589c1de43e3e4 SHA-1: eb36dfd7769a25286d7f72707ffd6d20faad598a SHA-256: 06b47f75b408c1d5b9a6c0ce741592a04dd279651d65be01785a0e4c04591b61
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a pattern often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a07a00a09a02a04/The-Princess-Bride-Deluxe-Edition-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/5a05a09a02a07/The-Princess-Bride-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/1a09a08a03a08a05/The-Princess-Bride-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/8a05a05a08a04a00/The-Princess-Bride---Folio-Society-Edition-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/1a02a04a06a02a08/The-Princess-Bride-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/2a07a06a07a04a01/The-Princess-Bride-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/4a05a03a03a07/The-Princess-Bride-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/4a04a03a01a02a02/The-Princess-Bride-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/5a02a02a08a02/The-Princess-Bride-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/7a06a00a00a00a08/The-Key-to-Skandos-A-tale-of-adventure-love-and-magic-by-William-A-Prater.pdf
    • http://muicuiu.dumb1.com/2a04a09a01a06a04/Love-Script-Deluxe-Edition-by-Tiffany-Ashley.pdf
    • http://muicuiu.dumb1.com/4a03a06a01a02a06/High-Adventure-The-True-Story-of-the-First-Ascent-of-Everest-by-Edmund-Hillary.pdf
    • http://muicuiu.dumb1.com/3a09a03a01a00a04/William-Goldman-Four-Screenplays-with-Essays-by-William-Goldman.pdf
    • http://muicuiu.dumb1.com/9a09a00a03a02a03/High-Seas-Cthulhu-Swashbuckling-Adventure-Meets-the-Mythos-by-William-Jones.pdf
    • http://muicuiu.dumb1.com/2a07a05a03a09a01/Truer-Than-True-Romance-Classic-Love-Comics-Retold-by-Jeanne-Martinet.pdf
    • http://muicuiu.dumb1.com/4a01a07a09a08a00/The-White-Masai-My-Exotic-Tale-of-Love-and-Adventure-by-Corinne-Hofmann.pdf
    • http://muicuiu.dumb1.com/4a01a07a09a05a06/California-Love-Sweet-Valley-High-TV-Edition-1-by-Francine-Pascal.pdf
    • http://muicuiu.dumb1.com/4a03a09a01a06a08/THE-KING-AND-HIS-QUEEN-A-Tale-Of-Love-One-True-Match-by-Zo-Bo.pdf
    • http://muicuiu.dumb1.com/1a08a00a01a04a02/Unraveled-A-Tale-of-True-Love-by-Julie-Daines.pdf
    • http://muicuiu.dumb1.com/4a02a05a03a08a01/Free-And-Easy-Bride-An-Erotic-Tale-of-a-Slutty-Cheating-Bride-by-Heidi-Deepkiss.pdf