Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bb843fb156faefe…

MALICIOUS

PDF

29.2 KB Created: 2019-04-30 01:57:30 +01:00 Authoring application: mPDF 5.7
MD5: a55dc54193975dacc8b88f5ff82f17ee SHA-1: 0dff386f8887b0a4f33b59e17d7713bc85b8d38d SHA-256: 2bb843fb156faefe5516460aac9b682038a3fc7922d1621397b2b6d7402a256f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a link farm with 32 external PDF links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while labeled as confirmed benign in isolation, are part of a larger malicious infrastructure designed to redirect users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9700

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a09a00a02a07/Tell-Me-the-Stories-of-Jesus-The-Parables-for-Children-by-Nancy-Regensburger.pdf
    • http://muicuiu.dumb1.com/4a02a02a02a04a01/Revisiting-the-Parables-of-Jesus-Ancient-stories-contemporary-audience-by-Lisa-L-pez-Smith.pdf
    • http://muicuiu.dumb1.com/8a08a09a04a06a04/THE-MESSAGE-OF-THE-PARABLES-by-J-F-McFADYEN-M-A-D-D-New-light-on-the-26-parables-of-Jesus-Christ-by-Joseph-Ferguson-McFadyen.pdf
    • http://muicuiu.dumb1.com/7a06a08a00a02a01/ANANSI-STORIES---13-West-African-Anansi-Children-s-Stories-13-Anansi-or-Aunt-Nancy-Stories-for-children-by-Anon-E-Mouse.pdf
    • http://muicuiu.dumb1.com/9a09a05a08a00a04/The-Parables-of-Jesus-by-Joachim-Jeremias.pdf
    • http://muicuiu.dumb1.com/8a02a07a09a06/The-Parables-of-Jesus-by-John-F-MacArthur-Jr-.pdf
    • http://muicuiu.dumb1.com/1a01a03a04a05a06a07/Buddhist-Parables-and-Other-Stories-by-Paul-Carus.pdf
    • http://muicuiu.dumb1.com/1a00a05a08a09a02a02/Dom-Im-Licht---Licht-Im-Dom-Vom-Umgang-Mit-Licht-in-Sakralbauten-in-Geschichte-Und-Gegenwart-by-Regensburger-Regensburger-Domstiftung.pdf
    • http://muicuiu.dumb1.com/1a08a05a00a09a02/Children-s-book-Monkey-Brains--Kids-Hillarious-Action-amp-Adventure-book-Bedtime-stories-for-children-short-stories-for-kids-Childrens-books-stories-reader-Funny-Action-and-Adventure-story-by-Nelson-Boyce.pdf
    • http://muicuiu.dumb1.com/2a07a09a06a07a08/Evolve-2-Vampire-Stories-of-the-Future-Undead-Otherworld-Stories-10-1-by-Nancy-Kilpatrick.pdf
    • http://muicuiu.dumb1.com/3a09a09a02a04a06/Children-s-Picture-Book-Clothes-Have-Feelings-Too-Charlie-Learns-to-Care-for-His-Things-Bedtime-Stories-Collection-Children-s-Books-with-Good-Values-by-Ari-Mazor.pdf
    • http://muicuiu.dumb1.com/3a01a03a02a00a04/Thanksgiving-Children-s-Stories-Funny-and-A-Bit-Scary-Stories-that-Kids-Love-by-Betty-J-Byers.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a08a08a01/The-Children-s-Bible-Genesis-1-1-11-9-Hebrew-Bible-Old-Testament-Stories-for-Children-by-Nicky-Stuart-Verra.pdf
    • http://muicuiu.dumb1.com/3a01a03a05a04a08/Light-amp-Lovable-Thanksgiving-Holiday-Stories-Wild-and-free-short-stories-for-children-simple-fun-books-for-kids-by-Betty-J-Byers.pdf
    • http://muicuiu.dumb1.com/3a01a06a09a01a05/Jesus-Son-Stories-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/4a03a05a00a07a03/Books-for-Children---My-Best-Unicorn-Good-Dream-Story-2-Free-Kids-Books-Beginning-Reader-Bedtime-Stories-For-Kids-Ages-3-8-children-s-books-by-Aurora-Higgins.pdf
    • http://muicuiu.dumb1.com/2a04a04a01a05a08/Book-of-Mormon-Stories-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://muicuiu.dumb1.com/1a07a08a01a04a04/Jesus-Freaks-Stories-of-Revolutionaries-Who-Changed-Their-World-Fearing-God-Not-Man-by-D-C-Talk.pdf
    • http://muicuiu.dumb1.com/1a00a05a09a00a02a08/Kr-hentisch-by-Hans-Regensburger.pdf
    • http://muicuiu.dumb1.com/1a03a06a05a04a01/Fountain-of-Age-Stories-by-Nancy-Kress.pdf
    • http://muicuiu.dumb1.com/7a06a08a00a02a01/ANANSI-STORIES---13-West-