Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ba31286aae76857…

MALICIOUS

PDF

23.3 KB Created: 2019-05-02 01:33:44 +01:00 Authoring application: mPDF 5.7
MD5: 8428428dfb756b8dd2cd9dbd2be8c131 SHA-1: 0c1d6175f8507c427d27a2b75bdf8ddb95711a02 SHA-256: 1ba31286aae76857910a732f0ced2a84f92df6af18eaa927f5f887deefffb8e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a lure to a website, potentially for SEO manipulation or to serve further malicious content. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a05a05a04a04a07/The-Civil-War-Day-By-Day-An-Almanac-1861-1865-by-E-B-Long.pdf
    • http://muicuiu.dumb1.com/6a08a01a05a08/A-Blaze-of-Glory-Civil-War-1861-1865-Western-Theater-1-by-Jeff-Shaara.pdf
    • http://muicuiu.dumb1.com/6a06a07a04a07/A-Chain-of-Thunder-Civil-War-1861-1865-Western-Theater-2-by-Jeff-Shaara.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a08a00/The-Image-of-War-1861-1865-Volume-1-Shadows-of-the-Storm-by-William-C-Davis.pdf
    • http://muicuiu.dumb1.com/2a03a03a02a04/The-Organization-and-Administration-of-the-Union-Army-1861-1865-Volume-I-by-Fred-Albert-Shannon.pdf
    • http://muicuiu.dumb1.com/2a03a03a02a06/The-Organization-and-Administration-of-the-Union-Army-1861-1865-Volume-II-by-Fred-Albert-Shannon.pdf
    • http://muicuiu.dumb1.com/3a03a02a01a02a03/Bluff-Bluster-Lies-and-Spies-The-Lincoln-Foreign-Policy-1861-1865-by-David-Perry.pdf
    • http://muicuiu.dumb1.com/5a00a09a01a04a08/The-Anatomy-of-the-Confederate-Congress-A-Study-of-the-Influence-of-Member-Characteristics-on-Legislative-Voting-Behavior-1861-1865-by-Thomas-Benjamin-Alexander.pdf
    • http://muicuiu.dumb1.com/2a04a07a03a00a03/The-Sacred-Moon-Tree-Being-the-True-Account-of-the-Trials-and-Adventures-of-Phoebe-Sands-in-the-Great-War-Between-the-States-1861-1865-by-Laura-Jan-Shore.pdf
    • http://muicuiu.dumb1.com/5a01a00a09a07a02/The-Union-Cavalry-in-the-Civil-War-From-Fort-Sumter-to-Gettysburg-1861-1863-by-Stephen-Z-Starr.pdf
    • http://muicuiu.dumb1.com/1a05a04a00a03a04/A-Light-in-the-Storm-The-Civil-War-Diary-of-Amelia-Martin-Fenwick-Island-Delaware-1861-by-Karen-Hesse.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a06a04/The-Diary-of-George-Templeton-Strong-Vol-3-The-Civil-War-1860-1865-by-George-Templeton-Strong.pdf
    • http://muicuiu.dumb1.com/2a04a04a08a05a02/The-Old-Farmer-s-Almanac-for-Kids-Volume-2-by-Old-Farmer-39-s-Almanac.pdf
    • http://muicuiu.dumb1.com/2a05a03a07a05a07/The-Killer-Angels-The-Classic-Novel-of-the-Civil-War-The-Civil-War-Trilogy-2-by-Michael-Shaara.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a09a08/The-Civil-War-150-An-Essential-To-Do-List-for-the-150th-Anniversary-by-Civil-War-Trust.pdf
    • http://muicuiu.dumb1.com/4a08a09a04a07a06/The-Killer-Angels-A-Novel-of-the-Civil-War-The-Civil-War-Trilogy-2-by-Michael-Shaara.pdf
    • http://muicuiu.dumb1.com/7a05a09a01a07a06/Gump-s-Since-1861-by-Roseman-Birmingham.pdf
    • http://muicuiu.dumb1.com/2a09a03a01a01a03/Epiphany-of-the-Long-Sun-The-Book-of-the-Long-Sun-3-4-by-Gene-Wolfe.pdf
    • http://muicuiu.dumb1.com/7a07a09a00a04/A-Long-Long-Sleep-UniCorp-1-by-Anna-Sheehan.pdf
    • http://muicuiu.dumb1.com/5a04a06a07a09/Exodus-from-the-Long-Sun-The-Book-of-the-Long-Sun-4-by-Gene-Wolfe.pdf