Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d0cec9d52019778…

MALICIOUS

PDF

24.5 KB Created: 2019-04-30 01:56:04 +01:00 Authoring application: mPDF 5.7
MD5: 0263d8d6815362429f1b2f45ff5b1c83 SHA-1: f1f6dbea80fc201543440c40346e6adb30939c8b SHA-256: 1d0cec9d5201977811b93edeaf354dbbbe0e774243369edce21f5ad36f5c26d7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs themselves are classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a06a02a07a00a04/Homeland-The-Graphic-Novel-Legend-of-Drizzt-The-Graphic-Novel-1-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a06a02a06a02a07/The-Halfling-s-Gem-The-Graphic-Novel-Legend-of-Drizzt-The-Graphic-Novel-6-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a07a06a04a06a02/Legend-of-Drizzt-Collector-s-Edition-Vol-1-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a00/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a03a08a05a06a09/Hero-Homecoming-3-The-Legend-of-Drizzt-30-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a04a06a08a07/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a08a08a03a07/Rise-of-the-King-Companions-Codex-2-Legend-of-Drizzt-26-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a01a06a00a07a07/Gauntlgrym-Forgotten-Realms-Neverwinter-1-Legend-of-Drizzt-20-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a03a07a01a09/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a09a01a02a09/Night-of-the-Hunter-Companions-Codex-1-Legend-of-Drizzt-25-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/7a04a08a01a00/The-Two-Swords-Forgotten-Realms-Hunter-s-Blades-3-Legend-of-Drizzt-16-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a07a00a05a01/Sojourn-Forgotten-Realms-The-Dark-Elf-Trilogy-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/7a05a01a07a05/The-Halfling-s-Gem-Forgotten-Realms-Icewind-Dale-3-Legend-of-Drizzt-6-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a09a01a00a09a05/Sea-of-Swords-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a08a06a01a06/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a06a08a03a07/The-Crystal-Shard-Forgotten-Realms-Icewind-Dale-1-Legend-of-Drizzt-4-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a02a01/Siege-of-Darkness-Forgotten-Realms-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a07a09a05a09a09/Eagle-Strike-The-Graphic-Novel-Alex-Rider-The-Graphic-Novels-4-by-Antony-Johnston.pdf
    • http://muicuiu.dumb1.com/4a02a01a03a03a05/The-Lost-Hero-The-Graphic-Novel-The-Heroes-of-Olympus-The-Graphic-Novels-1-by-Robert-Venditti.pdf
    • http://muicuiu.dumb1.com/7a07a04a01a03/Point-Blanc-The-Graphic-Novel-Alex-Rider-The-Graphic-Novels-2-by-Antony-Johnston.pdf
    • http://muicuiu.dumb1.com/2a04a08a08a03a07/R