Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d8d0e2468d547af…

MALICIOUS

PDF

18.0 KB Created: 2019-04-30 05:11:56 +01:00 Authoring application: mPDF 5.7
MD5: 5c90068b56733dae81cdd407ced78303 SHA-1: 626b1e011508f603fe4d1662b3d226a99c347b7c SHA-256: 2d8d0e2468d547afa2c4b1fc7912dd42c436781a7a14c48228206ea2bca54917
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass external link farm, with 24 links pointing to various URLs. This is indicative of SEO poisoning or a redirection scheme to lead users to malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1
    • http://muicuiu.dumb1.com/3a03a07a08a03a08/Life-s-a-Bitch-The-Complete-Bitchy-Bitch-Stories-by-Roberta-Gregory.pdf
    • http://muicuiu.dumb1.com/5a08a09a01/Bitch-Planet-Vol-2-President-Bitch-by-Kelly-Sue-DeConnick.pdf
    • http://muicuiu.dumb1.com/5a03a04a08a04/Bitch-Reloaded-Bitch-2-by-Deja-King.pdf
    • http://muicuiu.dumb1.com/8a05a02a09a00a00/Boss-Bitch-Bitch-7-by-Deja-King.pdf
    • http://muicuiu.dumb1.com/8a05a02a09a02a04/Bitch-Chronicles-Bitch-Chronicles-1-5-by-Deja-King.pdf
    • http://muicuiu.dumb1.com/8a01a01a04/Rising-Vincent-and-Eve-1-by-Jessica-Ruben.pdf
    • http://muicuiu.dumb1.com/1a02a00a03a05a08/White-on-Black-by-Rub-n-Gonz-lez-Gallego.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a02a07/Lonliness-Of-The-Hedgehog-by-Ruben-Garcia-Cebollero.pdf
    • http://muicuiu.dumb1.com/5a07a08a04a02a02/Ruben-Toledo-Fashionation-by-Valerie-Steele.pdf
    • http://muicuiu.dumb1.com/6a06a09a04a04a08/Ma-monide-ou-l-autre-Mo-se-by-Maurice-Ruben-Hayoun.pdf
    • http://muicuiu.dumb1.com/9a00a04a07a03a09/Jugger-Der-Sport-aus-der-Endzeit-by-Ruben-Philipp-Wickenh-user.pdf
    • http://muicuiu.dumb1.com/2a03a07a04a06a09/Crossing-Over-A-Mexican-Family-on-the-Migrant-Trail-by-Rub-n-Mart-nez.pdf
    • http://muicuiu.dumb1.com/8a07a00a00a02a04/Warum-wir-alle-Idioten-sind-Typische-Denkfehler-und-wie-man-sie-vermeidet-by-Ruben-Mersch.pdf
    • http://muicuiu.dumb1.com/9a07a05a01a05a07/Der-Styleguide-Akzente-setzen---besser-aussehen---Illustrationen-von-Ruben-Toledo-by-Nina-Garc-a.pdf
    • http://muicuiu.dumb1.com/4a05a05a09a01/Visiting-Emily-Poems-Inspired-by-the-Life-and-Work-of-Emily-Dickinson-by-Sheila-Coghill.pdf
    • http://muicuiu.dumb1.com/1a08a01a08a09a02/A-Kiss-for-Emily-The-Emily-Stokes-Series-1-by-J-P-Galuska.pdf
    • http://muicuiu.dumb1.com/5a07a02a03a00a03/Customized-Version-of-Mass-Communication-Producers-and-Consumers-by-Brent-Ruben-Raul-Reis-Barbara-Iverson-and-Genelle-Belmas-by-Laurie-Fluker.pdf
    • http://muicuiu.dumb1.com/3a03a05a09a04a08/I-Hear-She-s-a-Real-Bitch-by-Jen-Agg.pdf
    • http://muicuiu.dumb1.com/1a00a08a01a04a05a04/When-A-Bitch-Fed-Up-by-Kevina-Hopkins.pdf
    • http://muicuiu.dumb1.com/2a09a04a02a09a00/Bitch-and-Famous-by-Cat-Caruthers.pdf