Malicious PDF — malware analysis report

Static analysis result for SHA-256 265afc927178f8f1…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 02:06:23 +01:00 Authoring application: mPDF 5.7
MD5: 78d43ec617ce2a6fc7e539c45942d810 SHA-1: fb5553017c149f0353789c85d30618e8a9e03e9d SHA-256: 265afc927178f8f1b1b13ec803c59dbd4569a53aa0ef56309591c74701916215
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly suggests maliciousness. The primary attack pattern involves directing users to a large collection of external PDF files, likely for SEO poisoning or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a03a07a06a00a07/The-Last-Detective-The-Forgotten-Man-The-Two-Minute-Rule-Elvis-Cole-9-10-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a02a03/Robert-Crais-Collection---Hostage-The-Two-Minute-Rule-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/2a01a08a02a00a00/The-Monkey-s-Raincoat-Elvis-Cole-1-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/1a07a01a05a04/Free-Fall-Elvis-Cole-4-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/9a04a04a03a07/Voodoo-River-Elvis-Cole-5-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/7a00a01a09/The-Wanted-Elvis-Cole-17-Joe-Pike-6-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a00a08/A-Dangerous-Man-An-Elvis-Cole-and-Joe-Pike-Novel-Book-18-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a05a09a00/The-Monkey-s-Raincoat-Stalking-The-Angel-Elvis-Cole-1-2-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a00a06/Free-Fall-Indigo-Slam-Elvis-Cole-4-7-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a05a09a07/The-Last-Detective-The-Forgotten-Man-Hostage-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a09a05/Novels-by-Robert-Crais-The-Monkey-s-Raincoat-the-Watchman-Chasing-Darkness-the-Last-Detective-the-Forgotten-Man-L-a-Requiem-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a01a05/Devil-s-Cantina-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/7a04a01a06a08a03/La-sentinelle-de-l-ombre-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/4a00a07a07a01a04/The-Watchman-Joe-Pike-1-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/1a00a03a00a02/Suspect-Scott-James-amp-Maggie-1-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a01a04/L-A-Requiem-by-Robert-Crais-l-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a00a04/Sunset-Express-by-Robert-Crais-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://muicuiu.dumb1.com/4a09a09a05a08/Elvis-is-Alive-by-Robert-Mickey-Maughon.pdf
    • http://muicuiu.dumb1.com/7a08a05a03a00a06/Elvis-Close-Up-Rare-Intimate-Unpublished-Photographs-of-Elvis-Presley-in-1956-by-Jay-B-Leviton.pdf
    • http://muicuiu.dumb1.com/2a06a03a03a03a00/Ragdoll-Detective-William-Fawkes-1-by-Daniel-Cole.pdf
    • http://muicuiu.dumb1.com/8a03a07a06a09a0