Malicious PDF — malware analysis report

Static analysis result for SHA-256 46b812081ae69202…

MALICIOUS

PDF

26.0 KB Created: 2019-04-30 01:59:42 +01:00 Authoring application: mPDF 5.7
MD5: 619975278dce98882e713b1c09a97c1c SHA-1: 823fcdb78e9c63e38fcd4df133462f454afa74bf SHA-256: 46b812081ae6920291be492562e58bda6be7223f18c6357660a5269ba8819977
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific content of the linked documents is benign, the sheer volume and structure suggest an attempt to manipulate search engine results or direct users to a large number of external resources. No scripts were extracted from this sample, and the document body was not sufficiently readable to determine a specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a04a01a06a05a06/The-Falls-of-Niagara-or-Tourist-s-Guide-to-This-Wonder-of-Nature-by-Samuel-De-Veaux.pdf
    • http://muicuiu.dumb1.com/8a04a01a04a05a02/The-Travellers-Own-Book-to-Saratoga-Springs-Niagara-Falls-and-Canada-a-Complete-Guide-for-the-Valetudinarian-and-for-the-Tourist-by-Samuel-De-Veaux.pdf
    • http://muicuiu.dumb1.com/8a04a01a06a05a08/The-falls-of-Niagara-or-Tourist-s-guide-to-this-wonder-of-nature-including-notices-of-the-whirlpool-islands-amp-c-and-a-complete-guide-thro-the-Canadas-by-Samuel-De-Veaux.pdf
    • http://muicuiu.dumb1.com/8a04a01a05a05a09/The-Travellers-Own-Book-to-Saratoga-Springs-Niagara-Falls-and-Canada-Containing-Routes-Distances-Conveyances-Expenses-Use-of-Mineral-Waters-Baths-Description-of-Scenery-Etc-A-Complete-Guide-for-the-Valetudinarian-and-for-the-Tourist-by-Veaux-Samuel-De.pdf
    • http://muicuiu.dumb1.com/8a04a01a05a06a04/The-Falls-of-Niagara-or-Tourist-s-Guide-to-This-Wonder-of-Nature-Including-Notices-of-the-Whirlpool-Islands-amp-c-and-a-Complete-Guide-Thro-the-Canadas-by-S-De-Veaux.pdf
    • http://muicuiu.dumb1.com/6a07a08a05a03/Niagara-Falls-All-Over-Again-by-Elizabeth-McCracken.pdf
    • http://muicuiu.dumb1.com/8a00a01a01a06a09/Niagara-A-History-of-the-Falls-by-Pierre-Berton.pdf
    • http://muicuiu.dumb1.com/2a00a07a08a01a07/Taken-by-the-Ghost-of-Napoleon-Bonaparte-s-Horny-Little-Brother-Jerome-at-Niagara-Falls-Taken-by-Things-2-by-Maddie-Montrose.pdf
    • http://muicuiu.dumb1.com/6a00a04a06a07a01/Field-Trip-To-Niagara-Falls-Geronimo-Stilton-24-by-Geronimo-Stilton.pdf
    • http://muicuiu.dumb1.com/8a04a01a04a05a04/A-Memoir-of-James-de-Veaux-of-Charleston-S-C-Member-of-the-National-Academy-of-Design-New-York-by-James-De-Veaux.pdf
    • http://muicuiu.dumb1.com/6a07a09a04a02/Obsession-Falls-Virtue-Falls-2-by-Christina-Dodd.pdf
    • http://muicuiu.dumb1.com/5a08a06a04a03/From-The-Falls-The-Falls-Trilogy-2-by-Heather-Renee.pdf
    • http://muicuiu.dumb1.com/2a09a05a07a07a08/Bridges-A-Tale-of-Niagara-by-D-K-LeVick.pdf
    • http://muicuiu.dumb1.com/5a09a07a08a01a01/Diary-of-Samuel-Pepys---Volume-26-January-February-1663-64-by-Samuel-Pepys.pdf
    • http://muicuiu.dumb1.com/5a00a07a03a07a04/Rabbi-Samuel-Ben-Meir-s-Commentary-On-Genesis-An-Annotated-Translation-by-Samuel-ben-Meir.pdf
    • http://muicuiu.dumb1.com/2a07a03a04a03a08/The-Infernals-A-Samuel-Johnson-Tale-Samuel-Johnson-vs-the-Devil-2-by-John-Connolly.pdf
    • http://muicuiu.dumb1.com/8a04a00a00a06a05/The-Arcadia-Falls-Chronicles-Omnibus-Arcadia-Falls-1-6-by-Jennifer-Malone-Wright.pdf
    • http://muicuiu.dumb1.com/7a02a02a00a01a04/Droga-do-Lake-Falls-Szepty-w-ciemno-ciach-Lake-Falls-3-by-Artur-K-Dormann.pdf
    • http://muicuiu.dumb1.com/8a08a05a07a08a03/The-Sheriff-of-Wickham-Falls-Wickham-Falls-Weddings-3-by-Rochelle-Alers.pdf
    • http://muicuiu.dumb1.com/4a03a05a00a08a03/Casket-Cache-Spencer-Funeral-Home-Niagara-Cozy-Mystery-1-by-Janice-J-Richardson.pdf
    • http://muicuiu.dumb1.com/8a04a01a05a05a09/The-Travellers-Own-Book-to-Saratoga-Springs-Niagara-Falls-and-Canada-Containing-Routes-Distances-Conveyances-Expenses-Use-of-Mineral-Waters-Baths-Description-of-Scenery-Etc-A-Complete-Guide-for-the-Valetudinarian-and-for-the-Tourist-by-Veaux-Samue