Malicious PDF — malware analysis report

Static analysis result for SHA-256 395a3a8da9ed00a1…

MALICIOUS

PDF

17.0 KB Created: 2019-05-01 11:58:59 +01:00 Authoring application: mPDF 5.7
MD5: a2e8fbc9d5c2c0fc6788a18b8831b831 SHA-1: fa887d32c9a0d68371ff55943e9c5c878d495862 SHA-256: 395a3a8da9ed00a1794940da4f5615e3519321b5f96149d43e76450224e559cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly suggests maliciousness. While no scripts were extracted, the sheer volume of links points to a likely SEO spam or redirection campaign, potentially leading to further malicious content. The primary attack pattern involves luring users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a02a06a05a04a01/Captured-by-the-Sheikh-Rivals-to-the-Crown-of-Kadar-1-by-Kate-Hewitt.pdf
    • http://muicuiu.dumb1.com/7a02a02a05a08a09/Lone-Wolfe-Bad-Blood-8-by-Kate-Hewitt.pdf
    • http://muicuiu.dumb1.com/1a09a05a01a07a07/Raptors-of-the-West-Captured-in-Photographs-by-Kate-Davis.pdf
    • http://muicuiu.dumb1.com/3a05a09a06a04a05/The-Sheikh-s-Blackmailed-Mistress-Sheikh-s-Arabian-Nights-6-by-Penny-Jordan.pdf
    • http://muicuiu.dumb1.com/7a08a07a08a03a02/Faite-pour-le-Sheikh-Matched-with-the-Sheikh-1-by-Alex-Anders.pdf
    • http://muicuiu.dumb1.com/1a00a04a08a01a07a00/Sheikh-in-a-Storm-Exotic-Adventures-for-Erotic-Nights-The-Samarkand-Sheikh-s-Harem-Book-2-by-Saffron-Rose.pdf
    • http://muicuiu.dumb1.com/1a00a04a08a01a06a04/Seduced-by-the-Sheikh-Erotic-Adventures-for-Exotic-Nights-The-Samarkand-Sheikh-s-Harem-Book-4-by-Saffron-Rose.pdf
    • http://muicuiu.dumb1.com/1a01a08a04a06a02/Kidnapped-By-The-Sheikh-The-Desert-Sheikh-1-by-Katheryn-Lane.pdf
    • http://muicuiu.dumb1.com/1a02a06a07a02a03/The-Sheikh-s-Son-The-Desert-Sheikh-3-by-Katheryn-Lane.pdf
    • http://muicuiu.dumb1.com/7a07a01a07a04a05/He-s-Captured-my-Trust-Captured-2-by-Karen-Frances.pdf
    • http://muicuiu.dumb1.com/1a04a06a09a07a03/Captured-Secret-Captured-1-by-April-Raynne.pdf
    • http://muicuiu.dumb1.com/7a07a01a07a04a09/Captured-by-our-Addiction-Captured-5-by-Karen-Frances.pdf
    • http://muicuiu.dumb1.com/7a07a01a07a00a06/He-s-Captured-my-Heart-Captured-1-by-Karen-Frances.pdf
    • http://muicuiu.dumb1.com/4a04a09a09a08/The-Gathering-Storm-Crown-of-Stars-5-by-Kate-Elliott.pdf
    • http://muicuiu.dumb1.com/7a08a01a06a09a07/The-Gypsy-Crown-Chain-of-Charms-1-by-Kate-Forsyth.pdf
    • http://muicuiu.dumb1.com/4a05a07a01a07a04/King-s-Dragon-Crown-of-Stars-1-by-Kate-Elliott.pdf
    • http://muicuiu.dumb1.com/2a02a01a06a06a01/The-Midsummer-Crown-Roger-the-Chapman-20-by-Kate-Sedley.pdf
    • http://muicuiu.dumb1.com/7a08a05a00a07a06/Kadar-Koli-6-by-David-Hadbawnik.pdf
    • http://muicuiu.dumb1.com/7a08a05a00a07a03/Kadar-Koli-5-by-David-Hadbawnik.pdf
    • http://muicuiu.dumb1.com/3a00a06a09a09a00/The-Sheikh-s-Beloved-Sheikh-s-Beloved-1-2-by-Katheryn-Lane.pdf
    • http://muicuiu.dumb1.com/1a00a04a08a01a06a04/Seduced-by-the-Sheikh-Erotic-Adventures-for-Exotic-Nights-Th