Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f7d1f6b336cae11…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:10:15 +01:00 Authoring application: mPDF 5.7
MD5: 18a0b4384417069081e3a666fbd420e7 SHA-1: a2f1a87101af07d442bb7cdb0fd27315ca89a98b SHA-256: 2f7d1f6b336cae114428166441c0465cd936f0ad18ec42cd31db61ab693c1ef2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a06a05a00a01/The-Education-of-Kevin-Powell-A-Boy-s-Journey-into-Manhood-by-Kevin-Powell.pdf
    • http://muicuiu.dumb1.com/3a04a04a09a01a03/My-American-Journey-by-Colin-Powell.pdf
    • http://muicuiu.dumb1.com/4a07a07a03a01a00/To-Keep-The-Ball-Rolling-The-Memoirs-Of-Anthony-Powell-by-Anthony-Powell.pdf
    • http://muicuiu.dumb1.com/5a01a08a02a06/Keep-the-Faith-Vol-1-on-Education-by-Kevin-Swanson.pdf
    • http://muicuiu.dumb1.com/2a00a07a00a09a06/Down-the-Great-Unknown-John-Wesley-Powell-s-1869-Journey-of-Discovery-and-Tragedy-Through-the-Grand-Canyon-by-Edward-Dolnick.pdf
    • http://muicuiu.dumb1.com/1a01a06a07a00a09a01/Kevin-McCloud-s-Colour-Now-An-Expert-Guide-to-Choosing-Colours-for-Your-Home-by-Kevin-McCloud.pdf
    • http://muicuiu.dumb1.com/1a01a06a07a00a02a02/Kevin-McCloud-s-Principles-of-Home-Making-a-Place-to-Live-by-Kevin-McCloud.pdf
    • http://muicuiu.dumb1.com/1a09a07a06a08a00/Continental-Shift-A-Journey-in-Africa-s-Changing-Fortunes-by-Kevin-Bloom.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a06a06a07/Fever-by-V-K-Powell.pdf
    • http://muicuiu.dumb1.com/9a07a08a07a01a09/Building-Winning-Algorithmic-Trading-Systems-A-Trader-s-Journey-From-Data-Mining-to-Monte-Carlo-Simulation-to-Live-Trading-by-Kevin-Davey.pdf
    • http://muicuiu.dumb1.com/7a02a03a02a05/Priority-by-Aaron-B-Powell.pdf
    • http://muicuiu.dumb1.com/3a07a07a07a02a09/To-Protect-and-Serve-by-V-K-Powell.pdf
    • http://muicuiu.dumb1.com/3a07a07a06a09a01/Justifiable-Risk-by-V-K-Powell.pdf
    • http://muicuiu.dumb1.com/3a03a01a02a09a08/Edisto-by-Padgett-Powell.pdf
    • http://muicuiu.dumb1.com/1a05a01a07a09/Edisto-by-Padgett-Powell.pdf
    • http://muicuiu.dumb1.com/8a05a08a04a09a02/Malaika-by-William-R-Powell.pdf
    • http://muicuiu.dumb1.com/1a05a03a02a00a02/Voluntary-by-Aaron-B-Powell.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a08a05a01/The-Fremden-by-Claire-Powell.pdf
    • http://muicuiu.dumb1.com/3a09a09a05a07a02/Three-Into-One-by-Julie-Elizabeth-Powell.pdf
    • http://muicuiu.dumb1.com/8a05a08a04a09a01/Malaika-by-MR-William-R-Powell.pdf
    • http://muicuiu.dumb1.com/1a01a06a07a00a09a01/Kevin-McCloud-s-Colour-Now-An-Expert-Guide-to-Choosing-Colours-for-Your-Home-by-Kevin-M