Malicious PDF — malware analysis report

Static analysis result for SHA-256 2041bad2ff0d963d…

MALICIOUS

PDF

20.9 KB Created: 2019-05-02 00:43:29 +01:00 Authoring application: mPDF 5.7
MD5: b631b4c3ad6a7e1d31abe4881aa8fd17 SHA-1: fcc94e3ae2088639c83b4720e2a1e160a5cca5a7 SHA-256: 2041bad2ff0d963d59cb39e1cafe2a9642638cfc78ba283d18149eb8a74c0d83
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links resolve to benign book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely to manipulate search engine results or redirect users to harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a09a09a05a09a03/The-Fussy-Baby-Book-Parenting-Your-High-Need-Child-From-Birth-to-Age-Five-by-William-Sears.pdf
    • http://muicuiu.dumb1.com/1a00a08a09a02a05a04/Baby-Loves-by-William-Lach.pdf
    • http://muicuiu.dumb1.com/7a07a02a01a01a02/The-Baby-Nurse-Bible-Secrets-Only-a-Baby-Nurse-Can-Tell-You-about-Having-and-Caring-for-Your-Baby-by-Carole-Arsenault.pdf
    • http://muicuiu.dumb1.com/6a00a04a04a04/Baby-s-Bucket-Book-by-Carol-McCloud.pdf
    • http://muicuiu.dumb1.com/4a04a09a01a05a01/Beau-s-Baby-The-Sunset-Club-Book-4-by-A-C-Katt.pdf
    • http://muicuiu.dumb1.com/1a01a00a08a06a06a06/Baby-by-Christmas-The-McIntyre-Men-Book-5-by-Maggie-Shayne.pdf
    • http://muicuiu.dumb1.com/8a08a08a02a06a00/Brambley-Hedge-Baby-Book-by-Jill-Barklem.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a05a04/Mission-Baby-Tooth-Book-2-by-Carol-Bates-Hutchinson.pdf
    • http://muicuiu.dumb1.com/4a08a00a06a07a00/Baby-Animals-A-Preschool-Puppet-Book-by-Tadasu-Izawa.pdf
    • http://muicuiu.dumb1.com/2a00a02a08a01a04/Baby-Be-Mine-Thompson-amp-Sons-bonus-book-by-Vivian-Arend.pdf
    • http://muicuiu.dumb1.com/9a05a04a05a08a09/Baby-Light-A-children-s-book-for-the-family-HADRIAN-SERIES-1-by-Ina-I-Gjikondi-G.pdf
    • http://muicuiu.dumb1.com/6a05a04a08a09a08/The-Baby-Sitters-Club-Trivia-and-Puzzle-Fun-Book-by-Kara-Adamo.pdf
    • http://muicuiu.dumb1.com/9a05a06a02a07a05/Sir-William-and-the-Terror-Birds-as-told-by-Mac-Sir-William-s-Adventures-as-told-by-Mac-Book-1-by-P-J-Gilbers.pdf
    • http://muicuiu.dumb1.com/6a07a03a00a07a01/The-New-Contented-Little-Baby-Book-The-Secret-To-Calm-And-Confident-Parenting-by-Gina-Ford.pdf
    • http://muicuiu.dumb1.com/8a00a06a02a04a05/Heart-and-Humor-The-Picture-Book-Art-of-William-Steig-by-William-Steig.pdf
    • http://muicuiu.dumb1.com/5a07a03a06a02a04/Tossing-It-A-Navy-SEAL-and-Secret-Baby-Romance-Bronze-Bay-SEALS-Book-2-by-Rachel-Robinson.pdf
    • http://muicuiu.dumb1.com/9a04a04a08a00a08/Secrets-of-the-Baby-Whisperer-How-to-Calm-Connect-and-Communicate-with-Your-Baby-by-Tracy-Hogg.pdf
    • http://muicuiu.dumb1.com/4a00a00a02a03a06/Baby-Matters-What-Your-Doctor-May-Not-Tell-You-About-Caring-for-Your-Baby-by-Linda-Folden-Palmer.pdf
    • http://muicuiu.dumb1.com/4a00a03a03a01a05/Karen-s-Baby-Baby-Sitters-Little-Sister-Super-Special-5-by-Ann-M-Martin.pdf
    • http://muicuiu.dumb1.com/2a01a01a09a06a02/Boarding-the-Baby-Boat---A-guide-to-the-Baby-Decision-by-Imogen-Barnacle.pdf