Malicious PDF — malware analysis report

Static analysis result for SHA-256 1afcc4a8eb9e9006…

MALICIOUS

PDF

17.6 KB Created: 2019-04-28 12:46:01 +01:00 Authoring application: mPDF 5.7
MD5: cebc1311af446ca509e836e5d7d742fb SHA-1: 72d113605f8df930eb2c9837a57f2d285a9bbedb SHA-256: 1afcc4a8eb9e900683d1e997553dca12cff2647de17ab97f79ef9a2e399be417
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are labeled as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a00a03a04a02a06/The-Brass-Verdict-Mickey-Haller-2-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/3a02a07a09a08a04/The-Gods-of-Guilt-Mickey-Haller-5-Harry-Bosch-Universe-25-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/3a04a01a02a02a06/The-Lincoln-Lawyer-Novels-The-Lincoln-Lawyer-The-Brass-Verdict-The-Reversal-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/4a06a07a05a02a07/The-Reversal-Harry-Bosch-16-Mickey-Haller-3-Harry-Bosch-Universe-21-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/4a08a09a03a08a06/The-Reversal-Harry-Bosch-16-Mickey-Haller-3-Harry-Bosch-Universe-21-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/3a05a04a06a01a09/Michael-Connelly-CD-Collection-2-The-Concrete-Blonde-The-Last-Coyote-Trunk-Music-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/5a00a00a08a06a00/The-Scarecrow-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/3a09a02a06a01a02/The-Drop-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/6a09a04a06a03a08/The-Lincoln-Lawyer-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/5a03a08a09a07a09/La-Blonde-en-b-ton-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/7a06a05a05a00a02/Le-Coffre-oubli-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/4a09a01a04a04a07/Mulholland-Dive-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/5a03a08a09a07a06/Ceux-qui-tombent-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/4a06a06a02a09a00/Void-Moon-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/1a02a08a06a05a04/Chasing-the-Dime-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/5a02a06a02a07a09/Annie-s-Verdict-Michael-Gresham-7-Annie-the-Profiler-1-by-John-Ellsworth.pdf
    • http://muicuiu.dumb1.com/4a08a02a05a06a09/The-Scarecrow-Jack-McEvoy-2-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/7a07a08a07a04a04/Michael-The-Connelly-Cousins-3-by-Abbie-Zanders.pdf
    • http://muicuiu.dumb1.com/2a08a05a01a04a03/City-Of-Bones-Harry-Bosch-8-by-Michael-Connelly.pdf
    • http://muicuiu.dumb1.com/4a08a09a02a09a06/Angels-Flight-Harry-Bosch-6-by-Michael-Connelly.pdf