Malicious PDF — malware analysis report

Static analysis result for SHA-256 19a86766518dbbb1…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 05:37:42 +01:00 Authoring application: mPDF 5.7
MD5: beb29b4aef28c00260ca65b20547b864 SHA-1: 9910c7afcbaf1f50f93d43a5124b2365e2e6c738 SHA-256: 19a86766518dbbb1ae466fe10ecc67667c438e9e70dcb349436b1c6755649c54
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO poisoning or a similar technique to drive traffic to external content, rather than executing a direct payload from the PDF itself.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a03a07a01a02a00/S-CRATES-Y-LOS-TIGRES-AZULES-Un-an-lisis-cr-tico-de-la-Filosof-a-la-Historia-y-la-Literatura-by-Roberto-Barbery-Anaya.pdf
    • http://muicuiu.dumb1.com/1a05a08a08a02a01/Alburquerque-by-Rudolfo-Anaya.pdf
    • http://muicuiu.dumb1.com/4a00a04a07a04/Bless-Me-Ultima-by-Rudolfo-Anaya.pdf
    • http://muicuiu.dumb1.com/5a01a05a07a07a05/My-Land-Sings-by-Rudolfo-Anaya.pdf
    • http://muicuiu.dumb1.com/1a00a06a09a08a04a04/Sandok-n-Los-tigres-de-Mompracem-Versi-n-ntegra-y-anotada-Todo-Sandok-n-n-2-by-Emilio-Salgari.pdf
    • http://muicuiu.dumb1.com/6a03a07a00a07a03/babbleon-by-James-Barbery.pdf
    • http://muicuiu.dumb1.com/6a03a07a00a07a01/L-accueil-by-St-phane-Barbery.pdf
    • http://muicuiu.dumb1.com/1a05a08a06a03a06/The-Life-of-Elves-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/8a01a00a05a08/The-Elegance-of-the-Hedgehog-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/3a02a06a04a04/The-Elegance-of-the-Hedgehog-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/6a02a02a00a06a02/A-elegancia-do-ourizo-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/2a01a04a02a02a02/A-Eleg-ncia-Do-Ouri-o-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/6a03a07a00a06a05/Po-sie-Opus-1-by-St-phane-Barbery.pdf
    • http://muicuiu.dumb1.com/4a09a01a00a08a09/Gourmet-Rhapsody-by-Muriel-Barbery.pdf
    • http://muicuiu.dumb1.com/4a04a00a06a09a08/My-Fair-Invader-Allies-Of-The-Fae-Realm-Fated-Mates-Romance-Paranormal-Misfits-Book-4-by-C-J-Anaya.pdf
    • http://muicuiu.dumb1.com/1a01a09a01a08a00a08/Aproximaciones-Al-Estudio-de-la-Literatura-Hisp-nica-by-Carmelo-Virgillo.pdf
    • http://muicuiu.dumb1.com/1a01a09a01a09a04a04/Reflexiones-Introducci-n-a-la-Literatura-Hisp-nica-by-Rodney-T-Rodriguez.pdf
    • http://muicuiu.dumb1.com/8a09a06a00a04a09/Tres-siglos-de-literatura-infantil-europea-by-Bettina-Hurlimann.pdf
    • http://muicuiu.dumb1.com/7a05a07a07a03a02/Conexi-n-Literatura-Juvenil-A-Partir-De-12-A-os---Desconexi-n-by-Neal-Shusterman.pdf
    • http://muicuiu.dumb1.com/8a02a02a08a01a09/Letra-e-Tinta-10-Contos-Vencedores-do-Pr-mio-Mal-de-Literatura-by-Vagner-Amaro.pdf