Malicious PDF — malware analysis report

Static analysis result for SHA-256 35425400b11ddbdf…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 03:16:05 +01:00 Authoring application: mPDF 5.7
MD5: 16306c420b0aae67f8fd1354acd7ef19 SHA-1: c068de06d02f5bd07041a8fb94e3c145ff48b34d SHA-256: 35425400b11ddbdf80d635e9ccace2659c5ce265c9894befeb5ff2fa1e6ec24d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the extracted URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a02a05a05a07/Hero-s-Song-The-Songs-of-Eirren-1-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/3a04a03a03a03a04/East-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/7a06a09a07a08/North-Child-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/4a03a07a06a02a04/Two-Songs-Song-of-Prisoner-amp-Song-of-Malaya-by-Okot-p-39-Bitek.pdf
    • http://muicuiu.dumb1.com/8a06a02a06a02a01/Song-of-Songs-PB-by-Ariel-Bloch.pdf
    • http://muicuiu.dumb1.com/6a07a05a02a08a03/Lamentations-and-the-Song-of-Songs-by-Harvey-Cox.pdf
    • http://muicuiu.dumb1.com/9a09a01a01a02/My-Song-Of-Songs-Solomon-s-Touch-by-Joanna-Hynes.pdf
    • http://muicuiu.dumb1.com/4a05a09a09a01a03/The-Song-of-Songs-Love-Lyrics-from-the-Bible-by-Marcia-Falk.pdf
    • http://muicuiu.dumb1.com/4a09a08a03a06a03/The-Life-of-a-Song-The-fascinating-stories-behind-50-of-the-world-s-best-loved-songs-by-David-Cheal.pdf
    • http://muicuiu.dumb1.com/5a00a08a04a08a05/The-Sun-Has-Burned-My-Skin-A-Modest-Paraphrase-of-Solomon-s-Song-of-Songs-by-Adam-S-Miller.pdf
    • http://muicuiu.dumb1.com/1a01a09a05a02a02a02/Farewell-to-Shulamit-Spatial-and-Social-Diversity-in-the-Song-of-Songs-by-Carsten-L-Wilke.pdf
    • http://muicuiu.dumb1.com/1a01a01a06a01a02a06/Six-Songs-Op-34-No-2-quot-On-Wings-of-Song-quot-by-Felix-Mendelssohn.pdf
    • http://muicuiu.dumb1.com/9a08a05a03a00a04/The-House-of-Mirth-by-Edith-Wharton---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Edith-Wharton-by-Edith-Wharton.pdf
    • http://muicuiu.dumb1.com/1a00a06a06a00a05a02/Som-en-eld-ver-askan-Edith-S-dergrans-Fotografier-by-Edith-S-dergran.pdf
    • http://muicuiu.dumb1.com/8a00a09a05a07a00/Songs-of-Innocence-and-Songs-of-Experience-illustrated-Supreme-Edition-by-William-Blake.pdf
    • http://muicuiu.dumb1.com/9a08a00a09a07/Korean-Folk-Songs-Stars-in-the-Sky-and-Dreams-in-Our-Hearts-14-Sing-Along-Songs-with-the-Audio-CD-included-by-Robert-Choi.pdf
    • http://muicuiu.dumb1.com/4a04a06a02a00a07/Songs-of-Insurrection-The-Dragon-Songs-Saga-1-by-J-C-Kang.pdf
    • http://muicuiu.dumb1.com/1a04a06a06a01a05/Monica-Songs-of-Submission-7-5-Songs-of-Dominance-4-by-C-D-Reiss.pdf
    • http://muicuiu.dumb1.com/1a00a02a00a01a03/The-Tapestry-The-Life-and-Times-of-Francis-and-Edith-Schaeffer-by-Edith-Schaeffer.pdf
    • http://muicuiu.dumb1.com/9a01a05a09a05a02/The-Age-of-Innocence-The-Collected-Works-of-Edith-Wharton---43-Volumes-by-Edith-Wharton.pdf