Malicious PDF — malware analysis report

Static analysis result for SHA-256 2923ac76030bf502…

MALICIOUS

PDF

19.3 KB Created: 2019-05-05 16:25:04 +01:00 Authoring application: mPDF 5.7
MD5: 9e0d973e7219b6fbde2d80f84f3b421b SHA-1: 8450ebd99d73474f76295527f8e934fabb48640b SHA-256: 2923ac76030bf502941843e48cbe074f00c1f2e040646255586dfc5dc0ad267c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely to distribute spam or redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a02a00a00a03a07/Call-of-Kythshire-Keepers-of-the-Wellsprings-Book-One-by-Missy-Sheldrake.pdf
    • http://muicuiu.dumb1.com/1a07a06a02a02a06/The-World-Keepers-Three-Book-Set-Roblox-Fantasy-The-World-Keepers-1-3-by-Ty-The-Hunter.pdf
    • http://muicuiu.dumb1.com/6a03a02a07a05a02/Death-Comes-to-Dogwood-Manor-A-Missy-DuBois-Mystery-Book-4-by-Sandra-Bretting.pdf
    • http://muicuiu.dumb1.com/1a07a06a02a08a04/The-World-Keepers---Book-6-by-Ty-The-Hunter.pdf
    • http://muicuiu.dumb1.com/1a06a07a07a07a09/LUST-Book-Two-of-the-Shadow-Keepers-Series-by-Jas-T-Ward.pdf
    • http://muicuiu.dumb1.com/1a06a02a01a00a07/Bestow-The-Nature-Keepers-Series-Book-1-by-J-S-Kirkland.pdf
    • http://muicuiu.dumb1.com/6a05a08a04a00a02/Invisible-keepers-Guardian-Fairy-Book-1-by-Anastasia-Ducret.pdf
    • http://muicuiu.dumb1.com/3a09a07a06a08a01/Missy-Piggle-Wiggle-and-the-Sticky-Fingers-Cure-Missy-Piggle-Wiggle-3-by-Ann-M-Martin.pdf
    • http://muicuiu.dumb1.com/4a03a05a05a03a03/Morphic-Resonance-The-Nature-of-Formative-Causation-by-Rupert-Sheldrake.pdf
    • http://muicuiu.dumb1.com/4a06a01a02a04a06/The-Curse-Keepers-Collection-Curse-Keepers-1-3-5-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/4a03a05a05a02a08/Seven-Experiments-That-Could-Change-the-World-A-Do-it-yourself-Guide-to-Revolutionary-Science-by-Rupert-Sheldrake.pdf
    • http://muicuiu.dumb1.com/2a01a03a08a03a05/Missy-the-Werecat-Missy-the-Werecat-1-by-P-G-Allison.pdf
    • http://muicuiu.dumb1.com/4a03a05a05a09a06/Dogs-That-Know-When-Their-Owners-Are-Coming-Home-amp-Other-Unexplained-Powers-of-Animals-by-Rupert-Sheldrake.pdf
    • http://muicuiu.dumb1.com/3a05a09a05a00a03/Highland-Hunger-Book-1-Call-To-Arms-by-W-J-Watt.pdf
    • http://muicuiu.dumb1.com/2a09a08a08a00a05/The-Curse-Keepers-The-Curse-Keepers-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a05a08a09a08a03/Element-Keepers-Light-Element-Keepers-1-by-Isaac-Hamlet.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a09a03/Maya-Rising-Last-Call-for-Caviar-Book-2-by-Melissa-Roen.pdf
    • http://muicuiu.dumb1.com/8a00a09a03a06a00/When-the-Devil-Comes-To-Call-A-Lars-and-Shaine-Novel-Book-2-by-Eric-Beetner.pdf
    • http://muicuiu.dumb1.com/3a08a05a07a02a01/The-Keepers-of-Elenath-The-Keepers-of-Elenath-1-by-Amanda-Bradburn.pdf
    • http://muicuiu.dumb1.com/3a05a03a02a00a07/Follow-Me-A-Call-to-Die-A-Call-to-Live-by-David-Platt.pdf
    • http://muicuiu.dumb1.com/3a09a07a06a08a01/Missy-Piggle-Wiggle-and-the-Sticky-Fingers-Cure-Missy-Piggle-W