Malicious PDF — malware analysis report

Static analysis result for SHA-256 46dae013b752005b…

MALICIOUS

PDF

19.9 KB Created: 2019-05-06 16:42:31 +01:00 Authoring application: mPDF 5.7
MD5: a11eb151b8e875b4c79e76578cfc79fd SHA-1: 6c0e75fcbafd3cf1b76063e04ad0d3ad1d74b6e7 SHA-256: 46dae013b752005b6932099ebd54dff619a6f71db5e7ace1bcb61add2723c0f2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links resolve to benign-looking book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, possibly for SEO spam or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a03a09a03/A-Good-Girl-The-Charlie-McClung-Mysteries-2-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a08a07a04a08/Brilliant-Disguise-The-Charlie-McClung-Mysteries-1-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a09a09a00a01/Criminal-Kind-The-Charlie-McClung-Mysteries-3-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/3a03a06a06a03a02/Matriarch-Queen-Mary-and-the-House-of-Windsor-by-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/3a06a08/The-Good-Girl-by-Mary-Kubica.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a00a00a05/The-Thief-Who-Spat-In-Luck-s-Good-Eye-Amra-Thetys-2-by-Michael-McClung.pdf
    • http://muicuiu.dumb1.com/1a03a04a01a09a03/The-Best-Corpse-for-the-Job-Lindenshaw-Mysteries-1-by-Charlie-Cochrane.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5-Midnight-for-Charlie-Bone-Charlie-Bone-and-the-Time-Twister-Charlie-Bone-and-the-Invisible-Boy-Charlie-Bone-and-the-Castle-of-Mirrors-and-Charlie-Bone-and-the-Hidden-King-by-Jenny-Nimmo.pdf
    • http://muicuiu.dumb1.com/9a07a06a00a07/The-Fox-Princess-The-Rizwan-Sabir-Mysteries-2-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/4a04a01a09a08a03/The-Anne-Stories-Anne-of-Green-Gables-1-3-5-7-8-Story-Girl-1-2-by-L-M-Montgomery.pdf
    • http://muicuiu.dumb1.com/9a08a04a08a05/Blood-Honeymoon-The-Rizwan-Sabir-Mysteries-3-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/7a09a09a02a06a01/Murder-Most-Rural-The-Rizwan-Sabir-Mysteries-5-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/5a04a04a03/The-Girl-Who-Was-Taken-by-Charlie-Donlea.pdf
    • http://muicuiu.dumb1.com/1a09a05a05a02a08/Charlie-Presumed-Dead-by-Anne-Heltzel.pdf
    • http://muicuiu.dumb1.com/9a06a04a07a01a05/The-Blackmail-of-Evelynn-Faust-by-Shirley-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/2a03a04a03a02a02/Good-Grief-Charlie-Brown-Peanuts-Coronet-12-by-Charles-M-Schulz.pdf
    • http://muicuiu.dumb1.com/3a05a05a03a09a04/The-World-According-to-Tom-Hanks-The-Life-the-Obsessions-the-Good-Deeds-of-America-s-Most-Decent-Guy-by-Gavin-Edwards.pdf
    • http://muicuiu.dumb1.com/4a00a01a00a02a04/The-Incredible-Charlie-Carewe-by-Mary-Astor.pdf
    • http://muicuiu.dumb1.com/4a08a09a06a02/A-Girl-Named-Charlie-Lester-by-Carissa-Halston.pdf
    • http://muicuiu.dumb1.com/1a01a06a00a01a09a02/A-Good-Man-Gone-Mercy-Watts-Mysteries-1-by-A-W-Hartoin.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5-Midnight-for-Charlie-Bone-Charlie-Bone-and-the-Time-Twister-