Malicious PDF — malware analysis report

Static analysis result for SHA-256 2fa60b3f3b2c3cd4…

MALICIOUS

PDF

27.5 KB Created: 2019-05-07 04:01:03 +01:00 Authoring application: mPDF 5.7
MD5: 58caec011ccc6df7d845d834a955d7ef SHA-1: 6662d95e555ca1194762d4b4c18b786dee9639dd SHA-256: 2fa60b3f3b2c3cd40e8ac4419c5e8a6cf00cb6f447f49bbdd9d29b2f9cd326bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. These URLs point to external PDF files, suggesting a lure to download potentially malicious content disguised as books. The ML classifier also flagged this document as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a00a01a05a06a02/The-Tarot-Revealed-A-Modern-Guide-to-Reading-the-Tarot-Cards-by-Eden-Gray.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a07a07a04/Tarot-for-Beginners-A-Guide-to-Psychic-Tarot-Reading-Real-Tarot-Card-Meanings-and-Simple-Tarot-Spreads-by-Lisa-Chamberlain.pdf
    • http://muicuiu.dumb1.com/8a09a01a05a07a00/Simple-Fortunetelling-with-Tarot-Cards-Corrine-Kenner-s-Complete-Guide-by-Corrine-Kenner.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a08a05a07/Complete-Book-of-Tarot-Spreads-by-Evelin-B-rger.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a07a07a06/Tarot-Triumphs-Using-the-Tarot-Trumps-for-Divination-and-Inspiration-by-Cherry-Gilchrist.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a07a02a08/The-Tarot-of-Perfection-A-Book-of-Tarot-Tales-by-Rachel-Pollack.pdf
    • http://muicuiu.dumb1.com/8a01a09a03a03a02/Tarot-Talismans-Invoke-the-Angels-of-the-Tarot-by-Chic-Cicero.pdf
    • http://muicuiu.dumb1.com/7a07a03a04a08a05/The-Tarot-Bible-The-Definitive-Guide-to-the-Cards-and-Spreads-by-Sarah-Bartlett.pdf
    • http://muicuiu.dumb1.com/8a08a01a01a03a02/The-Soul-System-of-Tarot-How-Combining-Tarot-Astrology-and-Numerology-Can-Help-You-Discover-Your-True-Purpose-by-Austin-Muhs.pdf
    • http://muicuiu.dumb1.com/1a00a09a01a02a02a01/The-2-Hour-Tarot-Tutor-The-Fast-Revolutionary-Method-for-Learning-to-Read-Tarot-Cards-in-Two-Hours-by-Wilma-Carroll.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a05a08a02/Faith-of-Tarot-Tarot-3-by-Piers-Anthony.pdf
    • http://muicuiu.dumb1.com/2a00a02a02a00a09/Falling-for-Him---Karen-and-Robert-Complete-Collection-by-Jessica-Gray.pdf
    • http://muicuiu.dumb1.com/8a04a01a05a06a04/The-Falls-of-Niagara-or-Tourist-s-Guide-to-This-Wonder-of-Nature-Including-Notices-of-the-Whirlpool-Islands-amp-c-and-a-Complete-Guide-Thro-the-Canadas-by-S-De-Veaux.pdf
    • http://muicuiu.dumb1.com/8a04a01a06a05a08/The-falls-of-Niagara-or-Tourist-s-guide-to-this-wonder-of-nature-including-notices-of-the-whirlpool-islands-amp-c-and-a-complete-guide-thro-the-Canadas-by-Samuel-De-Veaux.pdf
    • http://muicuiu.dumb1.com/8a08a05a03a08a07/Tarot-Your-Everyday-Guide-Practical-Problem-Solving-and-Everyday-Advice-by-Janina-Renee.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a07a02a07/Tarot-A-New-Handbook-for-the-Apprentice-The-Connolly-Tarot-Revised-by-Eileen-Connolly.pdf
    • http://muicuiu.dumb1.com/1a01a01a05a04a04a06/Black-amp-Decker-The-Complete-Guide-to-Outdoor-Carpentry-Updated-2nd-Edition-Complete-Plans-for-Beautiful-Backyard-Building-Projects-by-Black-amp-Decker.pdf
    • http://muicuiu.dumb1.com/4a07a01a04a09a09/The-Natural-Kitchen-Your-Guide-to-the-Sustainable-Food-Revolution-by-Deborah-Eden-Tull.pdf
    • http://muicuiu.dumb1.com/1a01a00a08a09a05a01/The-Acid-Diaries-A-Psychonaut-s-Guide-to-the-History-and-Use-of-LSD-by-Christopher-Gray.pdf
    • http://muicuiu.dumb1.com/2a01a05a06a00a04/Eden-Eden-Eden-by-Pierre-Guyotat.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a07a07a06/Tarot-Triumphs-Using-the-Tarot-Trumps-for