Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e08fd44c0e48df4…

MALICIOUS

PDF

19.9 KB Created: 2019-05-07 04:28:20 +01:00 Authoring application: mPDF 5.7
MD5: 81daeee0974e261cf38ca51857450ee9 SHA-1: 013f0cb4671a9d0fb427e19ddb51b9b3d11c28d6 SHA-256: 2e08fd44c0e48df491aebd1bf2f16bd9807afc0862567d858a60d1d7297b88fa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links are currently classified as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a07a01a04a03a03/Million-Dollar-Party-A-Restaurant-Memoir-by-Robert-Mark-Ihrig.pdf
    • http://muicuiu.dumb1.com/4a01a00a00a09/A-Million-Dirty-Secrets-Million-Dollar-Duet-1-by-C-L-Parker.pdf
    • http://muicuiu.dumb1.com/8a06a09a05a00/A-Million-Guilty-Pleasures-Million-Dollar-Duet-2-by-C-L-Parker.pdf
    • http://muicuiu.dumb1.com/9a09a09a00a06a00/Million-Dollar-Ebay-Business-from-Home---A-Step-by-Step-Guide-Million-Dollar-Ebay-Business-from-Home---A-Step-by-Step-Guide-by-Neil-Waterhouse.pdf
    • http://muicuiu.dumb1.com/6a09a02a09a08a01/Million-Dollar-Words-by-Seth-Godin.pdf
    • http://muicuiu.dumb1.com/2a07a05a00a04a08/Million-Dollar-Outlines-by-David-Farland.pdf
    • http://muicuiu.dumb1.com/1a00a09a00a05a08/Feed-The-God-in-You-A-Million-Dollar-Book-by-S-J-Macurdy.pdf
    • http://muicuiu.dumb1.com/3a08a03a00a01a00/June-Sparrow-and-the-Million-Dollar-Penny-by-Rebecca-Chace.pdf
    • http://muicuiu.dumb1.com/1a03a05a05a06a02/The-Ultimate-Millionaire-The-Million-Dollar-Catch-3-by-Susan-Mallery.pdf
    • http://muicuiu.dumb1.com/5a08a02a03a03a08/Million-Dollar-Agent-Brokering-the-Dream-by-Josh-Flagg.pdf
    • http://muicuiu.dumb1.com/3a07a06a04a00a09/Million-Dollar-Baby-A-Marjorie-McClelland-Mystery-1-by-Amy-Patricia-Meade.pdf
    • http://muicuiu.dumb1.com/1a08a00a09a06a00/A-Dime-a-Dozen-The-Million-Dollar-Mysteries-3-by-Mindy-Starns-Clark.pdf
    • http://muicuiu.dumb1.com/1a08a01a00a05a07/The-Buck-Stops-Here-The-Million-Dollar-Mysteries-5-by-Mindy-Starns-Clark.pdf
    • http://muicuiu.dumb1.com/4a03a01a05a03/How-I-Braved-Anu-Aunty-amp-Co-Founded-A-Million-Dollar-Company-by-Varun-Agarwal.pdf
    • http://muicuiu.dumb1.com/9a00a09a03a00a02/The-Heart-is-a-Sleeping-Beauty-The-Million-Dollar-Hotel-by-Donata-Wenders.pdf
    • http://muicuiu.dumb1.com/9a07a08a02a04a02/Ron-Rooney-and-the-Million-Dollar-Comic-A-Stepping-Stone-Book-by-Susan-Schade.pdf
    • http://muicuiu.dumb1.com/4a09a05a09a06a05/-C-rock-Stories-Million-Dollar-Tales-of-Music-Mayhem-and-Immaturity-by-Dave-Brigham.pdf
    • http://muicuiu.dumb1.com/6a05a08a00a03a02/The-Million-Dollar-One-Person-Business-Make-Great-Money-Work-the-Way-You-Like-Have-the-Life-You-Want-by-Elaine-Pofeldt.pdf
    • http://muicuiu.dumb1.com/9a05a00a02a09/AM-I-STILL-AUTISTIC-How-a-Low-Functioning-Slightly-Retarded-Toddler-Became-CEO-of-a-Multi-Million-Dollar-National-Corporation-by-John-Hall.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a06a03a03/Im-Restaurant-und-anderswo-Hotel-Alpha-Stories-by-Mark-Watson.pdf
    • http://muicuiu.dumb1.com/3a08a03a00a01a00/June-Sparrow-and-the-Millio