Malicious PDF — malware analysis report

Static analysis result for SHA-256 25b029ef5d033a0a…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 08:10:41 +01:00 Authoring application: mPDF 5.7
MD5: 110ccb84c8d3b53476bbe98b89afd1eb SHA-1: 78f029688b47516d76fc3e8d58aa01ffc30163ce SHA-256: 25b029ef5d033a0a96036a7310304b9d242caf3cc119d12a3f86885121997347
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a04a00a05a07a04/The-Condor-And-The-Cows-A-South-American-Travel-Diary-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a05a07a00/Where-Joy-Resides-A-Christopher-Isherwood-Reader-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a05a09a02/Mr-Isherwood-Changes-Trains-Christopher-Isherwood-And-The-Search-For-The-Home-Self-by-Victor-Marsh.pdf
    • http://muicuiu.dumb1.com/3a05a09a06a04a07/Isherwood-on-Writing-The-Lectures-in-California-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a05a03a06/Isherwood-A-Biography-of-Christopher-Isherwood-by-Jonathan-Fryer.pdf
    • http://muicuiu.dumb1.com/4a03a08a08a06a00/Two-Wheels-Through-Terror-Diary-of-a-South-American-Motorcycle-Odyssey-by-Glen-Heggstad.pdf
    • http://muicuiu.dumb1.com/1a08a06a09a03a02/Christopher-and-His-Kind-1929-1939-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/4a07a02a06a02a05/Condor-and-Falcon-Condor-3-by-John-Simpson.pdf
    • http://muicuiu.dumb1.com/3a09a08a07a02a04/Christopher-and-His-Kind-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/4a04a07a02a07a07/Christopher-and-His-Kind-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a06a09a09/Sally-Bowles-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/4a03a01a03a08/Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/1a04a09a03a00a02/Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a05a09a05/Christopher-Isherwood-by-Stephen-Wade.pdf
    • http://muicuiu.dumb1.com/8a04a00a06a09a01/The-Wishing-Tree-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/4a00a08a06a00a03/Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a06a00a02/The-Berlin-of-Sally-Bowles-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a06a04a01/Christopher-Isherwood-A-World-In-Evening-by-Kay-Ferres.pdf
    • http://muicuiu.dumb1.com/3a02a08a02a03a03/Frankenstein-The-True-Story-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/8a04a00a06a04a02/Christopher-Isherwood-Encyclopedia-by-David-Garrett-Izzo.pdf
    • http://muicuiu.dumb1.com/1a08a06a09a03a02/Christopher-and-His-Kind-1929-1939-by-Christopher-Isherwood.p