Malicious PDF — malware analysis report

Static analysis result for SHA-256 4034c4478b1a7887…

MALICIOUS

PDF

20.4 KB Created: 2019-05-02 01:29:43 +01:00 Authoring application: mPDF 5.7
MD5: 03ff651baf312607917ddfc7f257b4c5 SHA-1: bdb3c066b032366e3ef030f9a5c5bcee31393f31 SHA-256: 4034c4478b1a78872d0776a237102d4a9c6d46029996820e454665e7fcfbd74f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS classifier firing suggest a malicious intent, likely related to SEO manipulation or distributing further malicious content. The document body is unreadable, preventing a more specific analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a09a02a07a09a07/Front-Word-Back-Word-Insight-Out-by-Smoky-Zeidel.pdf
    • http://muicuiu.dumb1.com/8a00a07a05a02a02/The-Word-Militant-Preaching-a-Decentering-Word-by-Walter-Brueggemann.pdf
    • http://muicuiu.dumb1.com/9a00a08a03a04a04/The-Everything-Giant-Book-of-Word-Searches-Volume-III-More-than-300-new-puzzles-for-the-biggest-word-search-fans-by-Charles-Timmerman.pdf
    • http://muicuiu.dumb1.com/1a09a08a08a02a04/Word-by-Word-Emancipation-and-the-Act-of-Writing-by-Christopher-Hager.pdf
    • http://muicuiu.dumb1.com/9a00a08a02a07a04/The-Everything-Giant-Book-of-Word-Searches-Over-300-puzzles-challenge-even-the-most-diehard-word-search-fans-Over-300-Puzzles-to-Challenge-Even-the-Most-Diehard-Word-Search-Fan-by-Charles-Timmerman.pdf
    • http://muicuiu.dumb1.com/1a06a07a01a09a06/The-Mangle-Street-Murders-The-Gower-Street-Detective-1-by-M-R-C-Kasasian.pdf
    • http://muicuiu.dumb1.com/1a04a04a04a00a05/Street-to-Street-by-Brian-Castro.pdf
    • http://muicuiu.dumb1.com/9a00a04a03a09a09/On-Gable-Street-LDS-Romance-Gable-Street-Collection-Book-2-by-Candice-Rose-Humes.pdf
    • http://muicuiu.dumb1.com/7a04a06a00a09a05/Bona-Fide-Street-Thug-II-quot-Street-Work-quot-by-Donald-Ray-Johnson.pdf
    • http://muicuiu.dumb1.com/7a05a04a02a00a00/The-Brothers-of-Baker-Street-Baker-Street-Letters-2-by-Michael-Robertson.pdf
    • http://muicuiu.dumb1.com/3a05a03a01a04a08/The-Baker-Street-Translation-Baker-Street-Letters-3-by-Michael-Robertson.pdf
    • http://muicuiu.dumb1.com/1a08a00a06a08a01/The-New-Evil-Fear-Street-Cheerleaders-4-Fear-Street-Superchiller-7-by-R-L-Stine.pdf
    • http://muicuiu.dumb1.com/2a00a09a00a00a02/Catching-the-Wolf-of-Wall-Street-More-Incredible-True-Stories-of-Fortunes-Schemes-Parties-and-Prison-The-Wolf-of-Wall-Street-2-by-Jordan-Belfort.pdf
    • http://muicuiu.dumb1.com/1a06a07a06a07a00/44-Scotland-Street-44-Scotland-Street-1-by-Alexander-McCall-Smith.pdf
    • http://muicuiu.dumb1.com/1a07a03a09a05a02/Return-to-Tradd-Street-Tradd-Street-4-by-Karen-White.pdf
    • http://muicuiu.dumb1.com/4a09a01a09a01a04/The-House-on-Tradd-Street-Tradd-Street-1-by-Karen-White.pdf
    • http://muicuiu.dumb1.com/1a06a09a02a03a09/Blossom-Street-Brides-Blossom-Street-10-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/8a01a05a09a09/Summer-on-Blossom-Street-Blossom-Street-6-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/4a01a07a08a07/The-Shop-on-Blossom-Street-Blossom-Street-1-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/6a08a08a09a08a09/Bergson-by-A-R-Lacey.pdf
    • http://muicuiu.dumb1.com/9a00a08a02a07a04/The-Everything-Giant-Book-of-Word-Searches-Over-300-puzzles-challenge-even-the-most-diehard-word-search-fans-Over-300-Puzzles-to-Challenge-Even-the-Most-Diehard-Word-Search-Fan-