Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b23f728a13de899…

MALICIOUS

PDF

21.4 KB Created: 2019-05-02 05:55:21 +01:00 Authoring application: mPDF 5.7
MD5: 15997ec405727c605fc2fbffb93a30ac SHA-1: 39b148dc1145a060f29a94c124fff6baffc5bab5 SHA-256: 1b23f728a13de8993a7e594aa4bc72505cd218d80bea1acb4d1409c2ddc3a03f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a05a09a09a00/Lucky-Bastard-A-Novel-by-Charles-McCarry.pdf
    • http://muicuiu.dumb1.com/1a00a04a05a06a03/Second-Sight-Paul-Christopher-7-by-Charles-McCarry.pdf
    • http://muicuiu.dumb1.com/1a00a04a08a07a01/The-Last-Supper-Paul-Christopher-5-by-Charles-McCarry.pdf
    • http://muicuiu.dumb1.com/7a01a01a09a01a01/Shelley-s-Heart-Paul-Christopher-8-by-Charles-McCarry.pdf
    • http://muicuiu.dumb1.com/6a06a03a05a05a05/Christopher-s-Ghosts-Paul-Christopher-10-by-Charles-McCarry.pdf
    • http://muicuiu.dumb1.com/3a06a09a04a09a01/Defeating-Dark-Angels-Breaking-Demonic-Oppression-in-the-Believer-s-Life-by-Charles-H-Kraft.pdf
    • http://muicuiu.dumb1.com/4a03a00a06a02a06/All-Our-Pretty-Songs-by-Sarah-McCarry.pdf
    • http://muicuiu.dumb1.com/1a00a00a06a03a08a09/Ein-Lied-so-s-und-dunkel-Metamorphoses-1-by-Sarah-McCarry.pdf
    • http://muicuiu.dumb1.com/7a07a03a03a08a01/Guillotine-Series-10-Meet-Me-In-Iram-Those-Are-Pearls-by-Sarah-McCarry.pdf
    • http://muicuiu.dumb1.com/8a08a00a02a04a06/Angels-101-An-Introduction-to-Connecting-Working-and-Healing-with-the-Angels-by-Doreen-Virtue.pdf
    • http://muicuiu.dumb1.com/3a08a05a01a04a05/Angels-at-the-Table-Angels-Everywhere-7-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/1a03a04a09a00a05/Starfire-Angels-Starfire-Angels-Dark-Angel-Chronicles-1-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/5a03a04a04a09/Angels-and-Spirit-Guides-How-to-Call-Upon-Your-Angels-and-Spirit-Guide-for-Help-by-Sylvia-Browne.pdf
    • http://muicuiu.dumb1.com/2a04a06a00a09a07/Fall-of-Angels-The-Complete-Trilogy-Fall-of-Angels-1-3-by-Keary-Taylor.pdf
    • http://muicuiu.dumb1.com/4a03a06a01a02/Strange-Angels-and-Betrayals-Strange-Angels-1-2-by-Lili-St-Crow.pdf
    • http://muicuiu.dumb1.com/5a09a01a07a09a09/Bleak-House-1852-by-Charles-Dickens-The-Ninth-Novel-by-Charles-Dickens-World-s-Classic-s-Bleak-House-Is-One-of-Charles-Dickens-s-Major-Novels-First-Published-as-a-Serial-Between-March-1852-and-September-1853-by-Charles-Dickens.pdf
    • http://muicuiu.dumb1.com/9a08a05a01a09a00/Great-Expectations-by-Charles-Dickens-Illustrated-Delphi-Parts-Edition-Charles-Dickens-by-Charles-Dickens.pdf
    • http://muicuiu.dumb1.com/1a01a04a07a06a09a06/Touched-By-Angels-Touched-By-Angels-1-by-Peggy-Webb.pdf
    • http://muicuiu.dumb1.com/4a00a09a02a05a05/Churchill-s-Angels-Churchill-s-Angels-1-by-Ruby-Jackson.pdf
    • http://muicuiu.dumb1.com/1a07a03a04a09a08/Dirty-Angels-Dirty-Angels-1-by-Karina-Halle.pdf