Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e828366e935afc5…

MALICIOUS

PDF

22.4 KB Created: 2019-04-30 04:11:04 +01:00 Authoring application: mPDF 5.7
MD5: 3d8449d591776a3dc4d33a3039654901 SHA-1: 45c63b34864b6575d094d0ef5857f9b7cb4716cf SHA-256: 3e828366e935afc5c7c32fe118c076cd37b1a9c1dbb7e131884ae0d5a8d5b201
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted appear benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to potentially harmful content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb
    • http://muicuiu.dumb1.com/3a05a08a06a02a08/Ajax-Penumbra-1969-Mr-Penumbra-s-24-Hour-Bookstore-0-5-by-Robin-Sloan.pdf
    • http://muicuiu.dumb1.com/5a09a03a00a06a02/Mr-Penumbra-s-24-Hour-Bookstore-Mr-Penumbra-s-24-Hour-Bookstore-1-by-Robin-Sloan.pdf
    • http://muicuiu.dumb1.com/2a01a05a03a04a00/Mr-Penumbra-s-24-Hour-Bookstore-Mr-Penumbra-s-24-Hour-Bookstore-1-by-Robin-Sloan.pdf
    • http://muicuiu.dumb1.com/2a09a09a03a06/Mr-Penumbra-39-s-24-Hour-Bookstore-by-Robin-Sloan.pdf
    • http://muicuiu.dumb1.com/7a05a08a04a00a07/A-Livraria-24-horas-do-Mr-Penumbra-Uma-divertida-e-emocionante-aventura-sobre-conspira-o-internacional-c-digos-secretos-amor-plat-nico---e-o-segredo-da-vida-eterna-Mr-Penumbra-s-24-Hour-Bookstore-1-by-Robin-Sloan.pdf
    • http://muicuiu.dumb1.com/5a01a07a04a04a08/Sloan-Rules-Alfred-P-Sloan-and-the-Triumph-of-General-Motors-by-David-Farber.pdf
    • http://muicuiu.dumb1.com/5a04a09a05a09a08/Robin-Sharma-75-Inspiring-and-Motivating-Life-Lessons-from-Robin-Sharma-Robin-Sharma-Robin-Sharma-Book-Robin-Sharma-Facts-Robin-Sharma-Lessons-Robin-Sharma-Words-by-Sami-S-Reed.pdf
    • http://muicuiu.dumb1.com/1a09a05a02a07a09/The-Midnight-Hour-A-Novella-The-Violet-Hour-Series-0-5-by-Andrea-L-Wells.pdf
    • http://muicuiu.dumb1.com/1a06a02a00a00a04/Saint-Sloan-Saint-Sloan-1-by-Kelly-Martin.pdf
    • http://muicuiu.dumb1.com/6a08a01a05a05a01/One-Hour-Cheese-Ricotta-Mozzarella-Ch-vre-Paneer--Even-Burrata-Fresh-and-Simple-Cheeses-You-Can-Make-in-an-Hour-or-Less-by-Claudia-Lucero.pdf
    • http://muicuiu.dumb1.com/8a03a06a05a01a05/Penumbra-by-Carolyn-Haines.pdf
    • http://muicuiu.dumb1.com/3a08a02a01a04a07/Ghost-s-Hour-Spook-s-Hour-by-Eve-Bunting.pdf
    • http://muicuiu.dumb1.com/3a04a08a01a08a07/Penumbra-The-Midnight-Society-2-by-Logan-Patricks.pdf
    • http://muicuiu.dumb1.com/1a00a08a02a05a00a07/Penumbra-Spook-Squad-3-by-Keri-Arthur.pdf
    • http://muicuiu.dumb1.com/1a04a02a08a02a08/A-Novel-Bookstore-by-Laurence-Coss-.pdf
    • http://muicuiu.dumb1.com/8a04a02a07a00a01/Overhead-Crane-Taining-Pack-by-ITI-bookstore.pdf
    • http://muicuiu.dumb1.com/8a04a02a06a03a09/Overhead-Crane-Taining-Pack-by-ITI-bookstore.pdf
    • http://muicuiu.dumb1.com/4a09a05a06a07a08/Quintessence-Enchanted-Bookstore-Legend-5-by-Marsha-A-Moore.pdf
    • http://muicuiu.dumb1.com/1a07a02a07a00a02/Seeking-a-Scribe-Enchanted-Bookstore-Legend-1-by-Marsha-A-Moore.pdf
    • http://muicuiu.dumb1.com/4a09a05a03a07a01/Lost-Volumes-Enchanted-Bookstore-Legend-3-by-Marsha-A-Moore.pdf