Malicious PDF — malware analysis report

Static analysis result for SHA-256 44a08a8fd54d506d…

MALICIOUS

PDF

33.3 KB Created: 2019-04-30 05:08:57 +01:00 Authoring application: mPDF 5.7
MD5: 7d541a10c69919b627e83577229c6eeb SHA-1: eb37e6fddb1780c76a44aacc2a499e193c03e8a3 SHA-256: 44a08a8fd54d506de53d6b0f86edee2c1fb298cc9599344457fb5e967537107c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS firing suggest a malicious intent, likely for SEO manipulation or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9723

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a06a01a02a00a06/2007-Writer-s-Market-by-Robert-Lee-Brewer.pdf
    • http://muicuiu.dumb1.com/1a00a05a03a03a09a01/2008-Writer-s-Market-by-Robert-Lee-Brewer.pdf
    • http://muicuiu.dumb1.com/6a04a06a03a04a01/2007-Report-on-Mayonnaise-The-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/6a04a06a03a08a06/The-2007-Report-on-Standard-Mayonnaise-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/1a01a08a08a06a00a05/2007-Report-on-Pin-Tumbler-Padlocks-The-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/6a04a06a03a08a09/The-2007-Report-on-Reduced-Calorie-Mayonnaise-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/5a09a02a00a01/Writer-s-Market-Companion-The-Essential-Guide-to-Starting-Your-Project-Getting-It-Published-and-Getting-Paid-by-Joe-Feiertag.pdf
    • http://muicuiu.dumb1.com/1a01a08a08a06a02a01/2007-Report-on-Commercial-Laundry-Drying-Tumblers-Attachments-and-Accessories-Excluding-Parts-The-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/8a05a08a06a02a05/Writer-on-a-Budget-Insider-tips-and-resources-to-help-you-write-polish-publish-and-market-your-book-at-minimal-cost-by-Sarah-Lentz.pdf
    • http://muicuiu.dumb1.com/9a04a05a01a02a02/2007-Report-on-Motor-Vehicle-Rubber-and-Plastic-Transmission-Belts-and-Belting-Excluding-Flat-Belts-and-Belting-The-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/9a04a05a01a02a00/2007-Report-on-Industrial-Rubber-and-Plastic-Transmission-Belts-and-Belting-Excluding-Flat-and-Fractional-Horsepower-Belts-and-Belting-The-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/6a04a06a04a04a09/The-2007-Report-on-Spoon-Type-Dressing-Sandwich-Spreads-Refrigerated-Dressings-and-All-Other-Semi-Solid-Type-Dressing-Excluding-Mayonnaise-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a00a05a05/Real-World-Sharepoint-2007-Indispensable-Experiences-from-16-Moss-and-Wss-Mvps-by-Robert-L-Bogue.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a00a05a06/Real-World-SharePoint-2007-Indispensable-Experiences-From-16-MOSS-and-WSS-MVPs-by-Robert-Bogue.pdf
    • http://muicuiu.dumb1.com/1a00a07a06a01a03a05/Automata-Languages-and-Programming-34th-International-Colloquium-ICALP-2007-Wroclaw-Poland-July-9-13-2007-Proceedings-by-Lars-Arge.pdf
    • http://muicuiu.dumb1.com/1a07a03a06a03/Death-of-A-Mystery-Writer-by-Robert-Barnard.pdf
    • http://muicuiu.dumb1.com/1a01a02a09a09a03a02/Advanced-Environmental-Chemical-And-Biological-Sensing-Technologies-V-10-11-September-2007-Boston-Massachusetts-Usa-by-Robert-A-Lieberman.pdf
    • http://muicuiu.dumb1.com/6a00a02a06a04a08/The-Panic-of-1907-Lessons-Learned-from-the-Market-s-Perfect-Storm-by-Robert-F-Bruner.pdf
    • http://muicuiu.dumb1.com/1a00a04a03a09a02a04/Cybernetic-Approach-to-Stock-Market-Analysis-Versus-Efficient-Market-Theory-by-Jerry-Felsen.pdf
    • http://muicuiu.dumb1.com/5a04a03a01a03a05/Tactical-Management-in-the-Secular-Bear-Market-How-Tactical-Management-and-Market-Phases-Can-Help-Manage-Risk-and-Make-Money-in-the-Secular-Bear-Market-by-Tahar-Mjigal.pdf
    • http://muicuiu.dumb1.com/1a01a08a08a06a00a05/2007-Report-on-Pin-Tumbler-Padlocks-The-World-Market-