Malicious PDF — malware analysis report

Static analysis result for SHA-256 2996e1a9a0de3d04…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 04:25:31 +01:00 Authoring application: mPDF 5.7
MD5: c37962cc3634d8ee1cabb8d6cbc9c7fa SHA-1: 6e45371b48765353c3c406315eb0eded1d7e28e4 SHA-256: 2996e1a9a0de3d041542509426288925f689cffbdb1a11329f6ae3aa66277d7f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and embedded URLs suggest a delivery mechanism for potentially harmful content, possibly related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a03a05a02a09a03/The-Secret-Mountain-The-Secret-Series-3-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/2a03a06a03a04a05/The-Secret-Of-Moon-Castle-The-Secret-Series-5-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/9a07a08a05a02a08/The-Secret-Seven-Adventure-The-Secret-Seven-2-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/7a04a03a07a03a03/Puzzle-for-the-Secret-Seven-The-Secret-Seven-10-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/9a07a08a05a02a09/Well-Done-Secret-Seven-The-Secret-Seven-3-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/9a07a08a06a06a04/Look-Out-Secret-Seven-The-Secret-Seven-14-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/3a09a03a01a03a05/The-Secret-Seven-Collection-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/1a01a01a08a03a01/The-Brave-Toy-Soldier-and-Other-Stories-Enid-Blyton-s-Popular-Rewards-Series-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/3a05a07a04a00a08/Enid-Blyton-s-Malory-Towers-6-Books-Collection-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/9a07a08a04a03a05/Enid-Blyton-Collection-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/5a03a00a04a01/Her-Secret-The-Secret-Series-2-by-Gina-A-Jones.pdf
    • http://muicuiu.dumb1.com/3a01a05a06a03a03/Secret-of-the-Mountain-Dog-by-Elizabeth-Cody-Kimmel.pdf
    • http://muicuiu.dumb1.com/1a04a03a07a00/The-Secret-of-Bruja-Mountain-by-Mary-Louise-Sherer.pdf
    • http://muicuiu.dumb1.com/3a07a07a03a08a08/Five-Get-into-a-Fix-Famous-Five-17-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/4a02a02a09a00/Five-Get-into-a-Fix-Famous-Five-17-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/3a07a07a03a07a08/7-Five-Go-Off-To-Camp-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/3a01a02a05a01a04/Well-Really-Mr-Twiddle-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/2a06a09a00a01a04/Four-In-A-Family-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/2a07a03a03a08a05/The-Adventures-of-Pip-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/2a07a04a04a06a04/Up-the-Faraway-Tree-by-Enid-Blyton.pdf
    • http://muicuiu.dumb1.com/1a01a01a08a03a01/The-Brave-Toy-Soldier-and-Other-Stories-Enid-Blyton-s-Popular-Rewards-Series-by-Enid