Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b885e7d2d7d9bc7…

MALICIOUS

PDF

22.0 KB Created: 2019-04-30 05:07:42 +01:00 Authoring application: mPDF 5.7
MD5: 0a7792828c675f87fd6488e281f8a4b5 SHA-1: 0b12e3926c17716a5b28cd5b9063f18e4a4e229c SHA-256: 2b885e7d2d7d9bc711dbd4c9ab85520941f193c78e8c690683fcaef3abe6725f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a link farm or redirection scheme. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a09a00a01/Criminal-Kind-The-Charlie-McClung-Mysteries-3-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a08a07a04a08/Brilliant-Disguise-The-Charlie-McClung-Mysteries-1-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a09a03a09a03/A-Good-Girl-The-Charlie-McClung-Mysteries-2-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/3a03a06a06a03a02/Matriarch-Queen-Mary-and-the-House-of-Windsor-by-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/1a03a04a01a09a03/The-Best-Corpse-for-the-Job-Lindenshaw-Mysteries-1-by-Charlie-Cochrane.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5-Midnight-for-Charlie-Bone-Charlie-Bone-and-the-Time-Twister-Charlie-Bone-and-the-Invisible-Boy-Charlie-Bone-and-the-Castle-of-Mirrors-and-Charlie-Bone-and-the-Hidden-King-by-Jenny-Nimmo.pdf
    • http://muicuiu.dumb1.com/9a07a06a00a07/The-Fox-Princess-The-Rizwan-Sabir-Mysteries-2-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/7a09a09a02a06a01/Murder-Most-Rural-The-Rizwan-Sabir-Mysteries-5-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/9a08a04a08a05/Blood-Honeymoon-The-Rizwan-Sabir-Mysteries-3-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/3a03a05a01a01a08/It-s-Criminal-The-True-Confessions-of-a-Jet-Set-Master-Criminal-by-James-Crosbie.pdf
    • http://muicuiu.dumb1.com/1a09a05a05a02a08/Charlie-Presumed-Dead-by-Anne-Heltzel.pdf
    • http://muicuiu.dumb1.com/9a06a04a07a01a05/The-Blackmail-of-Evelynn-Faust-by-Shirley-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/4a00a01a00a02a04/The-Incredible-Charlie-Carewe-by-Mary-Astor.pdf
    • http://muicuiu.dumb1.com/9a04a02a09a06a04/International-Criminal-Law-and-Sexual-Violence-Against-Women-The-Interpretation-of-Gender-in-the-Contemporary-International-Criminal-Trial-by-Daniela-Nadj.pdf
    • http://muicuiu.dumb1.com/6a06a02a02a06a09/International-criminal-responsibility-of-states-a-study-on-the-evolution-of-state-responsibility-with-particular-emphasis-on-the-concept-of-crime-and-criminal-responsibility-by-Farhad-Malekian.pdf
    • http://muicuiu.dumb1.com/2a03a06a08a08a06/Hannah-s-Hope-The-Morelville-Mysteries-8-by-Anne-Hagan.pdf
    • http://muicuiu.dumb1.com/3a01a06a04a06/Just-Desserts-Bed-and-Breakfast-Mysteries-1-by-Mary-Daheim.pdf
    • http://muicuiu.dumb1.com/2a09a01a02a03a02/Viva-Mama-Rossi-The-Morelville-Mysteries-5-by-Anne-Hagan.pdf
    • http://muicuiu.dumb1.com/9a04a08a04a04a00/The-Chaplet-of-Mary-The-Joyful-Mysteries-by-Michael-Hollings.pdf
    • http://muicuiu.dumb1.com/3a09a08a04a09a07/Butterfly-Boy-Avery-Barks-Dog-Mysteries-1-by-Mary-Hiker.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5