Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b91779a700c1dd4…

MALICIOUS

PDF

22.0 KB Created: 2019-05-01 16:41:35 +01:00 Authoring application: mPDF 5.7
MD5: 1964a68cd7ec2a5b3dc6face5794e23d SHA-1: 602fc798fc3ad9bdf25b272e4e67f4f2e97ed300 SHA-256: 1b91779a700c1dd4ed29d9a7b9442bfd1359cf749bb672a53389a12a79e92d2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely for SEO manipulation or to distribute further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a02a00a02a08a03/Le-Virus-Morningstar-T01-Le-Fleau-Des-Morts-by-ZACHARY-ALLAN-RECHT.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a04a03/Survivors-Morningstar-Strain-3-by-Z-A-Recht.pdf
    • http://muicuiu.dumb1.com/5a00a00a00a05a02/Plague-of-the-Dead-Morningstar-Strain-1-by-Z-A-Recht.pdf
    • http://muicuiu.dumb1.com/1a01a01a02a03a01a04/Mietvertrag-und-neue-Wohnung-Ihr-Recht-als-Mieter-Reihe-quot-Recht-kompakt-quot-5-by-Kai-Althoetmar.pdf
    • http://muicuiu.dumb1.com/9a00a08a05a03a00/Gesetzestexte-ffentliches-Recht---Grundlagen-Begleitband-zum-Lehrbuch-quot-ffentliches-Recht---Grundlagen-quot-Ausgabe-sterreich-by-Bruno-Binder.pdf
    • http://muicuiu.dumb1.com/6a02a00a03a04a07/Attila-le-fleau-de-dieu-by-Bouvier.pdf
    • http://muicuiu.dumb1.com/1a00a09a06a06a03a08/Leonhard-Christoph-Sturms-Vollstandige-Anweisung-Die-Bogen-Stellungen-Nach-Der-Civil-Bau-Kunst-in-Allen-Fallen-Recht-Einzutheilen-Mit-Zwey-Tabellen-Erklaret-Insonderheit-Von-Sieges-Bogen-Oder-Ehren-Pforten-Recht-Ausfuhrliche-Nachricht-Gegeben-by-Leonhard-Christoph-Sturm.pdf
    • http://muicuiu.dumb1.com/6a02a00a03a04a06/BPRD-Tome-03-Le-Fl-au-des-grenouilles-by-Mike-Mignola.pdf
    • http://muicuiu.dumb1.com/6a02a00a03a05a07/La-mal-diction-de-Gabrielle-Tome-1---Le-Fl-au-de-Dieu-ROMANS-HISTORIQ-by-Andrea-H-Japp.pdf
    • http://muicuiu.dumb1.com/8a08a09a00a09a02/Gloria-Rising-by-Linden-Morningstar.pdf
    • http://muicuiu.dumb1.com/2a06a08a09a06a04/Morningstar-Growing-Up-with-Books-by-Ann-Hood.pdf
    • http://muicuiu.dumb1.com/2a08a01a04a06a08/Daystar-Morningstar-3-by-Darcy-Town.pdf
    • http://muicuiu.dumb1.com/1a06a02a03a06/Marjorie-Morningstar-by-Herman-Wouk.pdf
    • http://muicuiu.dumb1.com/5a01a00a00a01a06/Grey-Ranks-by-Jason-Morningstar.pdf
    • http://muicuiu.dumb1.com/7a00a07a07a08a00/Le-Festin-des-Morts-by-Jean-Denis-Lu-ON.pdf
    • http://muicuiu.dumb1.com/8a01a05a07a03a00/Le-Temps-Des-Morts-Le-Reve-Russe-by-Pierre-Gascar.pdf
    • http://muicuiu.dumb1.com/4a03a04a03a06a04/Critic-s-Choice-Petit-Morts-9-by-Josh-Lanyon.pdf
    • http://muicuiu.dumb1.com/4a03a04a04a09a05/Other-People-s-Weddings-Petit-Morts-4-by-Josh-Lanyon.pdf
    • http://muicuiu.dumb1.com/7a03a00a02a07a04/Le-Camp-des-morts-Une-enqu-te-de-Walt-Longmire-by-Craig-Johnson.pdf
    • http://muicuiu.dumb1.com/8a05a04a02a05a01/Ecrire-ses-morts-Enqu-te-sur-un-usage-rituel-de-l-crit-dans-l-Egypte-pharaonique-by-Sylvie-Donnat-Beauquier.pdf
    • http://muicuiu.dumb1.com/9a00a08a05a03a00/Gesetzestexte-ffentliches-Recht---Grundlagen-Begleitband-zum-Lehrbuch-quot-ffentliches-Recht---Grundl