Malicious PDF — malware analysis report

Static analysis result for SHA-256 31d71c0aac98ecf6…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 02:51:11 +01:00 Authoring application: mPDF 5.7
MD5: 3aed98be31ae3a3afc87ce328be0d5d7 SHA-1: cb52a2d53fbc477fe63f57f537c0fd4f984de055 SHA-256: 31d71c0aac98ecf6b3bbb7457870155b13daf25c6711089cb550c9e1d54941aa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded URLs point to a domain that appears to be used for hosting a link farm, likely as a lure or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a05a02a09a07a00/Deja-Voodoo-by-Leslie-Brown.pdf
    • http://muicuiu.dumb1.com/8a05a02a09a06a08/Nikki-and-Deja-Wedding-Drama-Nikki-and-Deja-Book-Five-by-Karen-English.pdf
    • http://muicuiu.dumb1.com/8a05a02a09a06a00/Nikki-and-Deja-Birthday-Blues-Nikki-and-Deja-Book-Two-by-Karen-English.pdf
    • http://muicuiu.dumb1.com/1a07a02a08a09a04/Upbuilding-Black-Durham-Gender-Class-and-Black-Community-Development-in-the-Jim-Crow-South-by-Leslie-Brown.pdf
    • http://muicuiu.dumb1.com/1a09a07a00a03a09/Voodoo-Plague-Voodoo-Plague-1-by-Dirk-Patton.pdf
    • http://muicuiu.dumb1.com/7a09a08a00a08a00/Leslie-Peltier-s-Guide-to-the-Stars-Exploring-the-Sky-with-Binoculars-by-Leslie-C-Peltier.pdf
    • http://muicuiu.dumb1.com/4a05a03a01a01a04/The-Deja-Vu-Experiment-by-J-G-Renato.pdf
    • http://muicuiu.dumb1.com/6a02a02a08a05a09/Comic-Book-Dirty-Brown-A-successful-young-African-American-female-DJ-losses-her-power-to-entertain-her-fans-DJ-Dirty-Brown-Book-1-by-Tammy-Brown-Elkeles.pdf
    • http://muicuiu.dumb1.com/7a00a09a09a00a04/Deja-Who-Insighter-1-by-MaryJanice-Davidson.pdf
    • http://muicuiu.dumb1.com/8a01a05a02a07a08/Deja-Vu-Titan-7-5-by-Cristin-Harber.pdf
    • http://muicuiu.dumb1.com/8a05a02a08a07a01/Murder-Deja-Vu-by-Polly-Iyer.pdf
    • http://muicuiu.dumb1.com/2a04a00a07a05/Deja-Brew-by-Taneka-Stotts.pdf
    • http://muicuiu.dumb1.com/3a08a07a06a04a08/Deja-New-Insighter-2-by-MaryJanice-Davidson.pdf
    • http://muicuiu.dumb1.com/8a05a02a09a07a08/Then-There-Was-X-Deja-Series-by-Tajana-Sutton.pdf
    • http://muicuiu.dumb1.com/3a00a05a00a04a07/Deja-Vu-Sisterhood-19-by-Fern-Michaels.pdf
    • http://muicuiu.dumb1.com/3a02a03a06a02a02/Deja-Vu-Bride-by-Debra-Ullrick.pdf
    • http://muicuiu.dumb1.com/2a01a09a05a04a02/Something-Like-Voodoo-by-Rebecca-Hamilton.pdf
    • http://muicuiu.dumb1.com/8a05a03a00a07a00/Rich-Or-Famous-Part-2-by-Deja-King.pdf
    • http://muicuiu.dumb1.com/5a03a01a03a08a01/The-Explainer-From-Deja-Vu-To-Why-The-Sky-Is-Blue-And-Other-Conundrums-by-The-Conversation.pdf
    • http://muicuiu.dumb1.com/2a01a05a06a01a09/VooDoo-Souls-by-Ezekiel-Azazel-II.pdf
    • http://muicuiu.dumb1.com/7a00