Malicious PDF — malware analysis report

Static analysis result for SHA-256 31de36b22fc14cff…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 08:37:48 +01:00 Authoring application: mPDF 5.7
MD5: ca7ff93bd0366779191bf5e9a1d57714 SHA-1: 7c2e352cfb46ae8c93c099d754bf7eaa4bcceefe SHA-256: 31de36b22fc14cff0855547299ad544ca533ec8c11e9f4c485e3c23864679a7f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually marked as benign, collectively form a link farm, suggesting a potential SEO poisoning or traffic redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a03a00a03a05a08/Angelica-Kauffmann-R-A-Her-Life-and-Her-Works-by-V-Manners.pdf
    • http://muicuiu.dumb1.com/5a03a00a03a06a09/Serological-Diagnosis-Of-Salmonella-Species-Kauffmann-White-Schema-Scandinavian-University-Books-by-Fritz-Kauffmann.pdf
    • http://muicuiu.dumb1.com/5a08a00a00a02a07/Ang-lica-no-Fim-do-Arco--ris-Ang-lica-Marquesa-dos-Anjos-12-by-Anne-Golon.pdf
    • http://muicuiu.dumb1.com/5a03a00a03a03a00/Albums-of-early-life-by-Stanley-Kauffmann.pdf
    • http://muicuiu.dumb1.com/5a03a00a03a01a08/The-Millennial-Critic-Stanley-Kauffmann-on-Film-1999-2009-by-Stanley-Kauffmann.pdf
    • http://muicuiu.dumb1.com/1a01a02a04a01a04a00/Degas-Life-And-Works-by-Virginia-Spate.pdf
    • http://muicuiu.dumb1.com/4a08a01a09a02a01/The-Life-amp-Complete-Works-Of-Christopher-Marlowe-by-M-G-Scarsbrook.pdf
    • http://muicuiu.dumb1.com/1a00a02a08a06a02a03/Saadia-Gaon-His-Life-and-Works-by-Henry-Malter.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a05a06a09/Oskar-Panizza-His-Life-and-Works-by-Peter-D-G-Brown.pdf
    • http://muicuiu.dumb1.com/6a06a02a04a02a03/The-Life-and-Works-of-Vincent-Van-Gogh-by-Janice-Anderson.pdf
    • http://muicuiu.dumb1.com/9a05a04a09a09a05/Raffles-and-His-Creator-The-Life-and-Works-of-E-W-Hornung-by-Peter-Rowland.pdf
    • http://muicuiu.dumb1.com/6a09a01a04a03a01/The-Works-and-Life-of-Laurence-Sterne-The-Life-and-Opinions-of-Tristram-Shandy-Gentleman-by-Laurence-Sterne.pdf
    • http://muicuiu.dumb1.com/6a02a02a06a02a09/Razzle-Dazzle-The-Life-and-Works-of-Bob-Fosse-by-Kevin-Boyd-Grubb.pdf
    • http://muicuiu.dumb1.com/1a05a05a09a04/Friar-Thomas-D-Aquino-His-Life-Thought-and-Works-by-James-A-Weisheipl.pdf
    • http://muicuiu.dumb1.com/6a02a04a00a03a00/The-Life-And-Works-Of-Edgar-Allan-Poe-A-Psycho-Analytic-Interpretation-by-Marie-Bonaparte.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a03a02a05/The-life-and-works-of-Gotthold-Ephraim-Lessing-by-Adolf-Wilhelm-Theodor-Stahr.pdf
    • http://muicuiu.dumb1.com/2a00a08a07a00a04/The-Serengeti-Rules-The-Quest-to-Discover-How-Life-Works-and-Why-It-Matters-by-Sean-B-Carroll.pdf
    • http://muicuiu.dumb1.com/5a03a00a03a02a00/The-Perfectionist-by-Lane-Kauffmann.pdf
    • http://muicuiu.dumb1.com/2a08a03a00a08/The-Stone-Mason-of-Tor-House-The-Life-and-Works-of-Robinson-Jeffers-by-Melba-Berry-Bennet.pdf
    • http://muicuiu.dumb1.com/5a03a00a02a03a08/Angelika-Kauffmann-by-Waltraud-Maierhofer.pdf