Malicious PDF — malware analysis report

Static analysis result for SHA-256 40ebb2c4c6e7b4b5…

MALICIOUS

PDF

18.4 KB Created: 2019-05-07 03:30:14 +01:00 Authoring application: mPDF 5.7
MD5: 1b5d758cc5ae64f043e8c6b1db04e385 SHA-1: 0660e8943fdd2eb05687af528a9c88a95fb97c89 SHA-256: 40ebb2c4c6e7b4b50b54306ed64ed8234c4a492be572a91f95f8dc11d57d51da
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, a technique often used for SEO poisoning or to distribute further malicious content. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, with the first being http://muicuiu.dumb1.com/1a00a01a09a03a09/The-Journey-Living-by-Faith-in-an-Uncertain-World-by-Billy-Graham.pdf. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a01a09a03a09/The-Journey-Living-by-Faith-in-an-Uncertain-World-by-Billy-Graham.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a02a08/Nearing-Home-Life-Faith-and-Finishing-Well-by-Billy-Graham.pdf
    • http://muicuiu.dumb1.com/3a03a06a08a03a09/Conquering-Fear-Living-Boldly-in-an-Uncertain-World-by-Harold-S-Kushner.pdf
    • http://muicuiu.dumb1.com/1a01a09a06a07a06a07/Superstar-Billy-Graham-Tangled-Ropes-by-Billy-Graham.pdf
    • http://muicuiu.dumb1.com/3a05a04a05a00a04/An-Uncertain-Faith-by-Allie-Potts.pdf
    • http://muicuiu.dumb1.com/6a03a08a05a01/The-Secret-of-Happiness-by-Billy-Graham.pdf
    • http://muicuiu.dumb1.com/8a02a00a01a01a05/Billy-Graham-The-Great-Evangelist-by-Sam-Wellman.pdf
    • http://muicuiu.dumb1.com/4a04a03a02a04a06/Where-I-Am-Heaven-Eternity-and-Our-Life-Beyond-by-Billy-Graham.pdf
    • http://muicuiu.dumb1.com/4a09a07a08a02a03/The-Leadership-Secrets-of-Billy-Graham-by-Harold-Myra.pdf
    • http://muicuiu.dumb1.com/2a07a01a08a09a08/A-Prophet-with-Honor-The-Billy-Graham-Story-by-William-C-Martin.pdf
    • http://muicuiu.dumb1.com/3a06a07a03a03a08/The-Preacher-and-the-Presidents-Billy-Graham-in-the-White-House-by-Nancy-Gibbs.pdf
    • http://muicuiu.dumb1.com/2a05a07a07a03a01/Bravemouth-Living-With-Billy-Connolly-by-Pamela-Stephenson.pdf
    • http://muicuiu.dumb1.com/4a06a07a09a02a06/Tomorrow-Adventures-in-an-Uncertain-World-by-Bradley-Trevor-Greive.pdf
    • http://muicuiu.dumb1.com/6a05a00a02a03/A-New-Christianity-for-a-New-World-Why-Traditional-Faith-is-Dying-How-a-New-Faith-is-Being-Born-by-John-Shelby-Spong.pdf
    • http://muicuiu.dumb1.com/1a09a09a07a02/Epitaphs-for-the-Living-Words-and-Images-in-the-Time-of-AIDS-by-Billy-Howard.pdf
    • http://muicuiu.dumb1.com/1a01a02a06a08a03a07/1889-Journey-To-The-Moon-by-Billy-Kring.pdf
    • http://muicuiu.dumb1.com/4a09a08a00a08a08/God-Is-My-Coach-A-Business-Leader-s-Guide-to-Finding-Clarity-in-an-Uncertain-World-by-Larry-Julian.pdf
    • http://muicuiu.dumb1.com/2a02a08a02a09a09/How-to-Survive-the-End-of-the-World-as-We-Know-It-Tactics-Techniques-and-Technologies-for-Uncertain-Times-by-James-Wesley-Rawles.pdf
    • http://muicuiu.dumb1.com/4a05a07a02a08a08/The-Promise-of-Living-by-J-Lee-Graham.pdf
    • http://muicuiu.dumb1.com/9a05a06a06a01a08/The-Simplicity-of-Living-by-Faith-by-David-Corbin.pdf