Malicious PDF — malware analysis report

Static analysis result for SHA-256 091f41ea3e319146…

MALICIOUS

PDF

29.7 KB Created: 2019-04-29 23:23:41 +01:00 Authoring application: mPDF 5.7
MD5: 32ce4a899dcc7ef1a0a73ca4a7efbeb5 SHA-1: da17877cf258ac1d12da30a2313030cb73330a7a SHA-256: 091f41ea3e319146718ef1eb86b04b733c59459635c917cd5b03c398bfb3b9e4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged the PDF as malicious, the specific intent appears to be SEO poisoning or a link farm rather than direct payload delivery. The document body is heavily obfuscated, preventing analysis of its specific content, but the presence of numerous links to external PDFs on a suspicious domain is the primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9684

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a08a03a01a00a03/The-French-Language-Self-Taught-A-Manual-of-French-Idiomatic-Phraseology-Adapted-for-Students-for-Schools-and-for-Tourists-by-Alfred-Sardou.pdf
    • http://muicuiu.dumb1.com/1a01a00a01a05a04a05/Comparative-French-English-Studies-Grammatical-and-Idiomatic-Being-an-Entirely-Re-Written-Edition-of-the-French-Exercises-for-Middle-and-Upper-Forms-Adapted-to-the-Student-s-Comparative-French-Grammar-by-G-Eugene-Fasnacht.pdf
    • http://muicuiu.dumb1.com/5a05a02a01a04a07/Familypedia---French-Language-Articles-in-French-French-Speaking-Countries-La-Francophonie-Pages-in-French-Translations-Needed-Fr-User-Fr-Abraham-Coste-Baronnet-Beaudet-Brice-Baronnet-Charles-Borromee-Beaudet-Charles-Baronnet-by-Source-Wikia.pdf
    • http://muicuiu.dumb1.com/1a01a09a00a06a03a04/French-for-Business-Students-Book-5th-Edition-by-Lucette-Barbarin.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a03a08a01/Der-Neffe-ALS-Onkel-Translated-and-Adapted-from-the-French-of-Picard-Edited-with-Notes-and-Vocabulary-by-Louis-Beno-t-Picard.pdf
    • http://muicuiu.dumb1.com/3a00a05a07a04a05/The-Complete-French-for-Cats-French-for-Cats-amp-Advanced-French-for-Exceptional-Cats-by-Henry-N-Beard.pdf
    • http://muicuiu.dumb1.com/7a02a02a05a06a09/French-II---2nd-Ed-Rev-Euro-by-Pimsleur-Language-Programs.pdf
    • http://muicuiu.dumb1.com/5a03a07a05a07a03/A-French-Reader-Les-Conseils-d-un-Vieux-French-Readers-by-Yves-Thibault.pdf
    • http://muicuiu.dumb1.com/5a03a04a06a04a09/A-Very-French-Christmas-The-Greatest-French-Holiday-Stories-of-All-Time-by-Guy-de-Maupassant.pdf
    • http://muicuiu.dumb1.com/9a04a05a01a00a04/Hossfeld-s-New-Practical-Method-for-Learning-the-French-Language-by-A-P-Huguenet.pdf
    • http://muicuiu.dumb1.com/9a04a05a00a08a05/Hossfeld-s-new-practical-method-for-learning-the-French-language-by-A-P-Huguenet.pdf
    • http://muicuiu.dumb1.com/1a01a00a01a06a07a02/The-Student-s-Comparative-Grammar-of-the-French-Language-by-G-Eugene-Fasnacht.pdf
    • http://muicuiu.dumb1.com/7a09a08a04a09a07/Barron-s-AP-French-Language-and-Culture-with-Audio-CDs-by-Eliane-Kurbegov.pdf
    • http://muicuiu.dumb1.com/6a07a05a02a05a02/Origins-Of-French-Canadian-Families-Extracted-From-The-French-Civil-Statistics-First-Series-by-Archange-Godbout.pdf
    • http://muicuiu.dumb1.com/1a03a05a03a01a01/The-Everything-Learning-French-Book-Speak-Write-and-Understand-Basic-French-in-No-Time-by-Bruce-Sallee.pdf
    • http://muicuiu.dumb1.com/4a06a05a00a01a09/A-French-Song-in-New-York-The-French-Girl-6-by-Anna-Adams.pdf
    • http://muicuiu.dumb1.com/8a04a01a00a01a06/Rapports-An-Introduction-to-French-Language-and-Francophone-Culture-by-Joel-Walz.pdf
    • http://muicuiu.dumb1.com/5a08a03a03a05a06/Nouveaux-Copains-Foreign-Language-French-Level-1-by-Emmanuel-D-39-Usseau.pdf
    • http://muicuiu.dumb1.com/9a02a09a05a01a00/Cinderella-Cendrillon-Presented-by-Frendees-Dual-Language-English-French-by-Layer.pdf
    • http://muicuiu.dumb1.com/6a03a00a03a09a03/French-History-Introduction-Berry-Douane-Lacan-Treaty-of-Tours-Louis-the-Stammerer-Coutumes-de-Beauvaisis-French-Ship-Redoutable-by-Books-LLC.pdf