Malicious PDF — malware analysis report

Static analysis result for SHA-256 23ac4c05dbe4075a…

MALICIOUS

PDF

16.2 KB Created: 2019-04-30 02:25:58 +01:00 Authoring application: mPDF 5.7
MD5: f0e0512f8dc51a2a61d1bb2608f76c72 SHA-1: 088d8900322a18bd5f95ccfabc8bb2ebb6aa62d0 SHA-256: 23ac4c05dbe4075a05204b7a8074977add9792b88f5da5f61969b9cde925709f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs themselves are benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for other malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a02a01a01a02a06/Warrior-s-Song-by-Thomas-M-Hill.pdf
    • http://muicuiu.dumb1.com/2a00a00a09a02a01/Warrior-s-Song-Medieval-Song-1-by-Catherine-Coulter.pdf
    • http://muicuiu.dumb1.com/2a09a05a05a01a07/King-s-Warrior-The-Minstrel-s-Song-1-by-Jenelle-Leanne-Schmidt.pdf
    • http://muicuiu.dumb1.com/3a05a08a01a06a07/On-Wings-of-Song-by-Thomas-M-Disch.pdf
    • http://muicuiu.dumb1.com/7a01a03a04a06/Breakheart-Hill-by-Thomas-H-Cook.pdf
    • http://muicuiu.dumb1.com/3a01a04a07a01a03/The-Mare-on-the-Hill-by-Thomas-Locker.pdf
    • http://muicuiu.dumb1.com/1a00a01a03a05a01a09/The-McGraw-Hill-36-Hour-Course-Online-Marketing-by-Lorrie-Thomas.pdf
    • http://muicuiu.dumb1.com/2a02a02a01a04a06/Race-Ing-Justice-En-Gendering-Power-Essays-on-Anita-Hill-Clarence-Thomas-and-the-Construction-of-Social-Reality-by-Toni-Morrison.pdf
    • http://muicuiu.dumb1.com/3a09a09a01a07a06/Scarred-Warrior-Dark-Warrior-Alliance-4-by-Brenda-Trim.pdf
    • http://muicuiu.dumb1.com/3a09a08a02a02a03/Shattered-Warrior-Dark-Warrior-Alliance-8-by-Brenda-Trim.pdf
    • http://muicuiu.dumb1.com/4a07a04a05a01a02/Destiny-of-the-Female-Warrior-Nephilim-Warrior-2-by-Kate-Young.pdf
    • http://muicuiu.dumb1.com/1a08a08a07a09a06/Deviant-Warrior-Dark-Warrior-Alliance-3-by-Brenda-Trim.pdf
    • http://muicuiu.dumb1.com/1a02a02a05a09a05/The-Warrior-of-Clan-Kincaid-Highland-Warrior-3-by-Lily-Blackwood.pdf
    • http://muicuiu.dumb1.com/1a08a02a00a04a02/Dream-Warrior-Dark-Warrior-Alliance-1-by-Brenda-Trim.pdf
    • http://muicuiu.dumb1.com/4a05a01a07a09a07/Qualities-of-a-Spiritual-Warrior-Way-of-the-Warrior-Series-by-Graham-Cooke.pdf
    • http://muicuiu.dumb1.com/1a08a07a08a01a00/Mystik-Warrior-Dark-Warrior-Alliance-2-by-Brenda-Trim.pdf
    • http://muicuiu.dumb1.com/4a03a03a07a09a09/Warrior-s-Angels-Warrior-s-series-3-by-Rachel-Cron.pdf
    • http://muicuiu.dumb1.com/7a03a05a05a08a02/Warrior-En-Garde-The-Warrior-Trilogy-1-by-Michael-A-Stackpole.pdf
    • http://muicuiu.dumb1.com/2a09a09a03a00a00/Loved-By-a-Warrior-The-Warrior-King-2-by-Donna-Fletcher.pdf
    • http://muicuiu.dumb1.com/3a04a02a00a03a09/Wed-to-a-Highland-Warrior-The-Warrior-King-4-by-Donna-Fletcher.pdf
    • http://muicuiu.dumb1.com/3a09a09a01a07a06/Scarred-Warrior-Dark-Warrior-A