Malicious PDF — malware analysis report

Static analysis result for SHA-256 25b099fc16840903…

MALICIOUS

PDF

19.8 KB Created: 2019-05-07 04:30:05 +01:00 Authoring application: mPDF 5.7
MD5: 147315c3fca4e7a541df70f150c7dfea SHA-1: 358e2814f0a525d43d3d8b1184d909a269884ac9 SHA-256: 25b099fc168409037a6914181e40f68ecb0da6ab6f0208fa37bb994cf4b4a334
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a00a02a02a02/The-Happy-Hollisters-at-Sea-Gull-Beach-Happy-Hollisters-3-by-Jerry-West.pdf
    • http://muicuiu.dumb1.com/2a09a01a06a08a00/The-Happy-Addict-How-to-be-Happy-in-Recovery-from-Alcoholism-or-Drug-Addiction-by-Beth-Burgess.pdf
    • http://muicuiu.dumb1.com/1a09a01a04a01a05/How-We-Choose-to-Be-Happy-The-9-Choices-of-Extremely-Happy-People--Their-Secrets-Their-Stories-by-Rick-Foster.pdf
    • http://muicuiu.dumb1.com/6a09a06a02a00/The-Happy-Gospel-Effortless-Union-with-a-Happy-God-by-Benjamin-Dunn.pdf
    • http://muicuiu.dumb1.com/5a08a06a07a01a01/Happy-Dog-Happy-Human-A-Realization-of-Needs-amp-Wants-by-Matthew-Crans.pdf
    • http://muicuiu.dumb1.com/4a01a02a09a05a03/The-Simple-Habits-of-Happy-People-How-to-Go-from-Sad-to-Glad-in-21-Days-or-Less-by-Jerry-DiCairano.pdf
    • http://muicuiu.dumb1.com/1a01a02a02a04a06a05/Happy-Happy-Clover-Vol-2-by-Sayuri-Tatsuyama.pdf
    • http://muicuiu.dumb1.com/1a00a03a00a03a09/Happy-Chasing-Happy-by-Jerome-Isip.pdf
    • http://muicuiu.dumb1.com/3a09a09a09a01a06/More-Secrets-of-Happy-Children-Embrace-Your-Power-as-a-Parent--and-Help-Your-Children-be-Confident-Positive-Well-Adjusted-and-Happy-by-Steve-Biddulph.pdf
    • http://muicuiu.dumb1.com/7a00a00/Happy-Again-This-Is-What-Happy-Looks-Like-1-5-by-Jennifer-E-Smith.pdf
    • http://muicuiu.dumb1.com/1a08a07a08a02a09/Happy-Pants-Cafe-Happy-Pants-0-5-by-Mimi-Jean-Pamfiloff.pdf
    • http://muicuiu.dumb1.com/3a09a09a08a09a03/Good-Night-Sleep-Tight-The-Sleep-Lady-s-Gentle-Guide-to-Helping-Your-Child-Go-to-Sleep-Stay-Asleep-and-Wake-Up-Happy-by-Kim-West.pdf
    • http://muicuiu.dumb1.com/8a09a03a06a08a07/A-Happy-Man-by-Hansj-rg-Schertenleib.pdf
    • http://muicuiu.dumb1.com/9a01a06a08a04a01/Too-Happy-by-Kate-Kasten.pdf
    • http://muicuiu.dumb1.com/9a06a09a02a07/Oh-Happy-Day-by-Michelle-Ragoonanan-Ali.pdf
    • http://muicuiu.dumb1.com/2a02a04/After-Ever-Happy-After-4-by-Anna-Todd.pdf
    • http://muicuiu.dumb1.com/3a03a09a06a01a03/Happy-by-Chris-Scully.pdf
    • http://muicuiu.dumb1.com/1a02a05a01a01a08/The-Happy-Hypochondriac-by-Kat-Spitzer.pdf
    • http://muicuiu.dumb1.com/9a08a02a04a01a01/The-Happy-Egg-by-Ruth-Krauss.pdf
    • http://muicuiu.dumb1.com/2a02a08a05a02a04/Happy-Ever-After-by-Patricia-Scanlan.pdf