Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ba26f9d436f10d1…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 04:21:23 +01:00 Authoring application: mPDF 5.7
MD5: 8b5fa1e13eca232c6d6faf112896e2ec SHA-1: 03d06f85b96e0a30554c7f8127faa01e428797d3 SHA-256: 2ba26f9d436f10d15e1293161afebfeb9afb01760a6d14f280d5328c9ef648ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external documents, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While no scripts were extracted, the document body contains numerous URLs pointing to book titles, suggesting a potential SEO poisoning or link farm tactic to drive traffic or distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a00a06a03a06/The-Third-Eye-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a04a04a00a07/Peggy-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a00a03/Locked-in-Time-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a00a07a00a07a02/The-Twisted-Window-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a03a01a01a03/Summer-of-Fear-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/4a08a09a02a08a02/Debutante-Hill-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/2a04a00a05a03a04/Hotel-For-Dogs-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a01a02a09a05a05/Hotel-for-Dogs-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/4a08a01a01a07a05/The-Birthday-Moon-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/1a02a04a08a05a07/Debutante-Hill-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/3a08a06a03a08a01/Mystery-of-the-Missing-Map-Adventures-of-the-Northwoods-9-by-Lois-Walfrid-Johnson.pdf
    • http://muicuiu.dumb1.com/6a03a01a04a00a03/Authors-and-the-Works-Their-Books-Inspired-Meg-Cabot-Ann-Brashares-and-Lois-Duncan-by-London-Grace.pdf
    • http://muicuiu.dumb1.com/1a04a07a06a04a01/Who-Killed-My-Daughter-The-True-Story-of-a-Mother-s-Search-for-Her-Daughter-s-Murderer-by-Lois-Duncan.pdf
    • http://muicuiu.dumb1.com/2a04a05a00a03a01/Mandie-and-the-Missing-Schoolmarm-Mandie-Books-39-by-Lois-Gladys-Leppard.pdf
    • http://muicuiu.dumb1.com/6a08a08a04a08a02/The-Last-Fancy-Dan-The-Duncan-Mc-Kenzie-Story-by-Duncan-McKenzie.pdf
    • http://muicuiu.dumb1.com/3a03a05a00a00a00/Missing-Wives-Missing-Lives-True-Crime-Library-RJPP-5-by-J-J-Slate.pdf
    • http://muicuiu.dumb1.com/7a07a03a09a07a05/The-Missing-Girl-Innocent-amp-Missing-Book-2-by-Joli-Torres.pdf
    • http://muicuiu.dumb1.com/4a05a06a04a08/Sister-Missing-Girl-Missing-2-by-Sophie-McKenzie.pdf
    • http://muicuiu.dumb1.com/2a08a03a04a09a00/Damn-Good-Advice-For-People-with-Talent-How-To-Unleash-Your-Creative-Potential-by-America-s-Master-Communicator-George-Lois-by-George-Lois.pdf
    • http://muicuiu.dumb1.com/7a03a06a04a05a08/Lois-Lowry-by-Lois-Markham.pdf