Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d355535abb87d3b…

MALICIOUS

PDF

15.9 KB Created: 2019-04-30 00:00:57 +01:00 Authoring application: mPDF 5.7
MD5: 58f8881e75c44c29169180d438ba60f5 SHA-1: 3430f69ee50b96b91f40149c71e4886dea5f4d6a SHA-256: 1d355535abb87d3be59638a54e3852f2695844b9083a7d7283a5fa712d893b87
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with 21 external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually classified as benign, collectively form a pattern indicative of SEO poisoning or a similar content-luring technique. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a05a08a06a09/Chasing-Darkness-by-Julie-Cassar.pdf
    • http://muicuiu.dumb1.com/1a02a03a06a04a02/Across-a-Star-Swept-Sea-For-Darkness-Shows-the-Stars-2-by-Diana-Peterfreund.pdf
    • http://muicuiu.dumb1.com/3a06a08a02a03a00/The-First-Star-to-Fall-For-Darkness-Shows-the-Stars-1-5-by-Diana-Peterfreund.pdf
    • http://muicuiu.dumb1.com/7a04a06a00a05a02/La-constance-de-l-toile-polaire-For-Darkness-Shows-the-Stars-1-by-Diana-Peterfreund.pdf
    • http://muicuiu.dumb1.com/3a07a05a04a08a02/Hidden-in-the-Stars-Falling-Stars-2-by-Sadie-Grubor.pdf
    • http://muicuiu.dumb1.com/1a00a01a05a02a08/Falling-Stars-Shooting-Stars-5-by-V-C-Andrews.pdf
    • http://muicuiu.dumb1.com/6a06a01a02a05a01/Stars-of-the-Stars-Tome-1-by-Joann-Sfar.pdf
    • http://muicuiu.dumb1.com/3a04a01a09a08a09/Stars-So-Sweet-All-Four-Stars-3-by-Tara-Dairman.pdf
    • http://muicuiu.dumb1.com/1a06a03a00a03a08/The-Stars-Down-Under-The-Outback-Stars-2-by-Sandra-McDonald.pdf
    • http://muicuiu.dumb1.com/2a09a03a04a04a09/Julie-amp-Julia-365-days-524-recipes-1-tiny-apartment-kitchen-by-Julie-Powell.pdf
    • http://muicuiu.dumb1.com/6a00a00a09a09a07/Mies-Julie-Based-on-August-Strindberg-s-Miss-Julie-by-Yael-Farber.pdf
    • http://muicuiu.dumb1.com/1a03a05a05a07a03/Meet-Julie-American-Girls-Julie-1-by-Megan-McDonald.pdf
    • http://muicuiu.dumb1.com/1a04a02a05a00a01/Julie-s-Journey-American-Girls-Julie-5-by-Megan-McDonald.pdf
    • http://muicuiu.dumb1.com/3a05a00a01a06a02/Enlightened-by-Darkness---Vol-3-As-Darkness-Spreads-Enlightened-By-Darkness-3-by-Robert-Friedrich.pdf
    • http://muicuiu.dumb1.com/5a09a06a05a01/When-Stars-Die-Stars-1-by-Amber-Forbes.pdf
    • http://muicuiu.dumb1.com/3a08a08a08a03a00/Across-the-Stars-Across-the-Stars-1-by-India-Masters.pdf
    • http://muicuiu.dumb1.com/4a01a02a05a01a01/There-Once-Were-Stars-There-Once-Were-Stars-1-by-Melanie-McFarlane.pdf
    • http://muicuiu.dumb1.com/1a03a07a02a04/Julie-Julie-of-the-Wolves-2-by-Jean-Craighead-George.pdf
    • http://muicuiu.dumb1.com/5a03a01a08a06a05/Eventually-Julie-Julie-amp-Friends-1-by-Anthea-Syrokou.pdf
    • http://muicuiu.dumb1.com/4a03a07a01a09/Scent-of-Darkness-Darkness-Chosen-1-by-Christina-Dodd.pdf
    • http://muicuiu.dumb1.com