Malicious PDF — malware analysis report

Static analysis result for SHA-256 24a7ab77b48f7534…

MALICIOUS

PDF

19.9 KB Created: 2019-05-08 18:43:47 +01:00 Authoring application: mPDF 5.7
MD5: dd105c2f43fa68d78fbbcbf2add1b7b8 SHA-1: 90e3117a75a47e3d23a7f0bd2b70e0ac351478c5 SHA-256: 24a7ab77b48f753425e487d0cd20f4f08b2ff3bb72c51946f84ed9fc97c312e4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were individually classified as benign, the sheer volume and structure suggest a malicious intent to direct users to potentially harmful content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a08a03a01/Good-Morning-Midnight-by-Lily-Brooks-Dalton.pdf
    • http://muicuiu.dumb1.com/7a01a09a01a02a07/The-Room-in-the-Dragon-Volant-by-J-Sheridan-Lefanu-Fiction-Horror-by-J-Sheridan-Le-Fanu.pdf
    • http://muicuiu.dumb1.com/4a04a04a01a07a09/The-Dark-Warrior-Series-The-Complete-Collection-Contains-Midnight-s-Master-Midnight-s-Lover-Midnight-s-Seduction-Midnight-s-Warrior-Midnight-s-Kiss-Surrender-novella-Dark-Warriors-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/6a08a03a02a09a01/Lily-and-the-Shining-Dragons-Lily-2-by-Holly-Webb.pdf
    • http://muicuiu.dumb1.com/1a08a07a03a08a02/Dash-amp-Lily-s-Book-of-Dares-Dash-amp-Lily-1-by-Rachel-Cohn.pdf
    • http://muicuiu.dumb1.com/2a00a08a07a07a01/Dash-amp-Lily-s-Book-of-Dares-Dash-amp-Lily-1-by-Rachel-Cohn.pdf
    • http://muicuiu.dumb1.com/2a08a00a00a02a02/Dash-amp-Lily-s-Book-of-Dares-Dash-amp-Lily-1-by-Rachel-Cohn.pdf
    • http://muicuiu.dumb1.com/1a01a03a02a08a09a01/The-Archie-Sheridan-and-Gretchen-Lowell-Series-Archie-Sheridan-amp-Gretchen-Lowell-1-3-by-Chelsea-Cain.pdf
    • http://muicuiu.dumb1.com/2a04a06a07a03a05/Meet-the-Earl-at-Midnight-Midnight-Meetings-1-by-Gina-Conkle.pdf
    • http://muicuiu.dumb1.com/6a09a04a05a03a04/13-Ways-to-Midnight-Book-One-A-Reverse-Harem-Young-Adult-Paranormal-Romance-The-Midnight-Saga-by-Rue-Volley.pdf
    • http://muicuiu.dumb1.com/2a04a05a00a00a01/Kiss-of-Midnight-Midnight-Breed-1-by-Lara-Adrian.pdf
    • http://muicuiu.dumb1.com/6a04a00a04a03a02/The-Midnight-Society-Midnight-Chronicles-1-by-Rhonda-Sermon.pdf
    • http://muicuiu.dumb1.com/3a01a05a04a08a02/Veil-of-Midnight-Midnight-Breed-5-by-Lara-Adrian.pdf
    • http://muicuiu.dumb1.com/8a01a01a09a05a05/The-Marquis-At-Midnight-Midnight-Masquerade-1-by-Kate-Harper.pdf
    • http://muicuiu.dumb1.com/3a04a04a09a08/Veil-of-Midnight-Midnight-Breed-5-by-Lara-Adrian.pdf
    • http://muicuiu.dumb1.com/2a08a04a07a04a07/Darker-After-Midnight-Midnight-Breed-10-by-Lara-Adrian.pdf
    • http://muicuiu.dumb1.com/5a07a05a07a04/Midnight-Crossroad-Midnight-Texas-1-by-Charlaine-Harris.pdf
    • http://muicuiu.dumb1.com/3a06a00a08a04a05/Midnight-Promises-Men-of-Midnight-2-by-Lisa-Marie-Rice.pdf
    • http://muicuiu.dumb1.com/3a05a07a04a03a07/Midnight-Rising-Midnight-Breed-4-by-Lara-Adrian.pdf
    • http://muicuiu.dumb1.com/4a07a03a00a01/Midnight-Man-Midnight-1-by-Lisa-Marie-Rice.pdf