Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b80102120d3c6f0…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 09:42:29 +01:00 Authoring application: mPDF 5.7
MD5: 1f9f204314fc51ee5260017b57a016e2 SHA-1: b07f46c2e989781a8a1e490adc8d7079dff6872c SHA-256: 3b80102120d3c6f077b040816653944f9625cf2c14b2f836551b6c805bdfeba1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, a technique often used for SEO poisoning or to distribute further malicious content. While the document body was not readable, the presence of numerous links suggests a traffic-driving or content-distribution attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a01a09a09a07a08/Mortality-Doctrine-The-Eye-of-Minds-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/7a01a00a01a08a08/The-Mortality-Doctrine-Series-The-Complete-Trilogy-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a09a02/James-Dashner-Books-2017-Checklist-Reading-Order-of-Infinity-Ring-Book-Series-The-13th-Reality-Series-The-Maze-Runner-Series-The-Mortality-Doctrine-Series-and-List-of-All-James-Dashner-Books-by-Platinum-List.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a09a09/James-Dashner-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Maze-Runner-Series-13th-Reality-Series-Morality-Doctrine-Series-Jimmy-Fincher-Series-Listabook-Series-Order-Book-22-by-Listabook.pdf
    • http://muicuiu.dumb1.com/1a02a01a09a05a08/The-Kill-Order-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/1a07a07a08a04a02/The-Maze-Runner-Series-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/7a08a08a09a04a05/Le-rem-de-mortel-L-preuve-3-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/4a05a06a07a08a08/The-Kill-Order-Maze-Runner-0-5-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/3a08a04a04a03a00/A-Gift-of-Ice-The-Jimmy-Fincher-Saga-2-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/8a03a01a07a04/The-Scorch-Trials-The-Maze-Runner-2-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/1a02a06a01a04a04/The-Fever-Code-The-Maze-Runner-5-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/2a00a09a04a04a06/The-Void-of-Mist-and-Thunder-The-13th-Reality-4-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/9a02a08a05a09a06/Der-Game-Master---Gegen-die-Spielregeln-Band-2-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/4a07a06a08a01/The-Journal-of-Curious-Letters-The-13th-Reality-1-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a02a05/Study-Guide-The-Maze-Runner-by-James-Dashner-by-SuperSummary.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a02a04/Study-Guide-The-Death-Cure-by-James-Dashner-by-SuperSummary.pdf
    • http://muicuiu.dumb1.com/6a09a02a01a05/The-Blade-of-Shattered-Hope-The-13th-Reality-3-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/6a01a03a02a03a05/The-Kill-Order-Maze-Runner-Book-Four-Origin-by-James-Dashner.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a01a09/The-Maze-Runner-by-James-Dashner-l-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a08a03/An-Unauthorized-Guide-to-James-Dashner-A-Short-Biography-of-the-Author-of-The-Maze-Runner-Article-by-Malcolm-Stone.pdf
    • http://muicuiu.dumb1.com/7a01a00a02a09a09/James-Dashner-Series-Reading-Order-amp