Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e3d2d75e3cf4407…

MALICIOUS

PDF

13.8 KB Created: 2019-05-02 01:32:19 +01:00 Authoring application: mPDF 5.7
MD5: f45778586584bb4e02490568ea18db95 SHA-1: 1176dbd675b8583ef0df1a86c01713f320541df4 SHA-256: 2e3d2d75e3cf440793f199e2cf549147c06e932471ae43ba7058f46800d7b118
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document was flagged by a critical heuristic for containing a mass external PDF link farm, with 21 links identified. The ML classifier also assigned a high probability of maliciousness. The embedded URLs, while individually marked as benign, collectively form a pattern indicative of SEO poisoning or a similar traffic-driving scheme, likely intended to lead users to malicious content or phishing sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a08a09a03a03a05/I-Hear-Your-Voice-by-Young-Ha-Kim.pdf
    • http://muicuiu.dumb1.com/5a05a00a03a03a01/How-to-Hear-the-Voice-of-God-by-Tanya-Guerrier.pdf
    • http://muicuiu.dumb1.com/9a08a06a01a00a09/How-To-Hear-The-Voice-Of-God-And-Understand-It-by-Adam-Houge.pdf
    • http://muicuiu.dumb1.com/2a08a00a02a02a08/Voice-Over-Seiyu-Academy-Vol-1-Voice-Over-1-by-Maki-Minami.pdf
    • http://muicuiu.dumb1.com/4a04a09a09a01a08/Her-Other-Voice-Her-Sister-s-Voice-2-by-Lesley-Cheetham.pdf
    • http://muicuiu.dumb1.com/3a00a08a08a04a02/Controlled-by-His-Voice-5-Controlled-by-His-Voice-5-by-Skylar-Cross.pdf
    • http://muicuiu.dumb1.com/1a07a01a00a01a05/Her-Master-s-Voice-Her-Master-s-Voice-1-2-by-Vivien-Sparx.pdf
    • http://muicuiu.dumb1.com/1a09a05a06a09a03/Hear-by-Robin-Epstein.pdf
    • http://muicuiu.dumb1.com/7a03a00a06a09a00/Do-You-Hear-Them-by-Nathalie-Sarraute.pdf
    • http://muicuiu.dumb1.com/3a03a05a09a04a08/I-Hear-She-s-a-Real-Bitch-by-Jen-Agg.pdf
    • http://muicuiu.dumb1.com/1a02a08a01a01a06/Speak-Softly-She-Can-Hear-by-Pam-Lewis.pdf
    • http://muicuiu.dumb1.com/6a01a07a02a09a03/You-Will-Hear-Thunder-by-Anna-Akhmatova.pdf
    • http://muicuiu.dumb1.com/3a00a02a02a01a08/No-One-to-Hear-You-Scream-by-Julia-Madeleine.pdf
    • http://muicuiu.dumb1.com/3a04a01a09a06a07/Mother-Can-You-Hear-Me-by-Margaret-Forster.pdf
    • http://muicuiu.dumb1.com/1a08a07a01a05a05/Speak-Softly-She-Can-Hear-by-Pam-Lewis.pdf
    • http://muicuiu.dumb1.com/3a09a02a00a09a00/If-You-Hear-Her-The-Ash-Trilogy-1-by-Shiloh-Walker.pdf
    • http://muicuiu.dumb1.com/3a03a07a02a03a01/Hear-Through-My-Ears-by-Tara-Chevrestt.pdf
    • http://muicuiu.dumb1.com/1a06a09a04a08a03/Did-You-Hear-What-Happened-to-Andrea-by-Gloria-D-Miklowitz.pdf
    • http://muicuiu.dumb1.com/2a09a04a08a09a09/Turn-On-the-Light-So-I-Can-Hear-by-Teri-Kanefield.pdf
    • http://muicuiu.dumb1.com/4a02a04a00a09/Hear-the-Wind-Sing-The-Rat-1-by-Haruki-Murakami.pdf