Malicious PDF — malware analysis report

Static analysis result for SHA-256 47fdc3080f22ceb7…

MALICIOUS

PDF

17.2 KB Created: 2019-05-07 06:02:35 +01:00 Authoring application: mPDF 5.7
MD5: 3041b1d76debe2c1f00327d01142eb55 SHA-1: c4d20318b4a879a01efa4ccf8da2d730b1067210 SHA-256: 47fdc3080f22ceb7729ad69bff66859dba749d4dfa132a3ea4fcc4e656c8c043
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, suggesting a tactic to distribute malicious content or engage in SEO poisoning. While the document body is unreadable, the structure and link farm strongly suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a03a05a01a08/Boston-s-Gun-Bible---Revised-with-2008-D-C-v-Heller-by-Boston-T-Party.pdf
    • http://muicuiu.dumb1.com/8a05a09a05a08a03/You-amp-The-Police-by-Boston-T-Party.pdf
    • http://muicuiu.dumb1.com/3a01a06a04a04a06/The-Boston-Tea-Party-by-Russell-Freedman.pdf
    • http://muicuiu.dumb1.com/5a01a09a00a09a09/How-Did-Tea-and-Taxes-Spark-a-Revolution-and-Other-Questions-about-the-Boston-Tea-Party-by-Linda-Gondosch.pdf
    • http://muicuiu.dumb1.com/7a07a02a05a06a01/The-Original-Fannie-Farmer-1896-Cookbook-The-Boston-Cooking-School-by-Boston-Cooking-School.pdf
    • http://muicuiu.dumb1.com/7a05a06a04a09a09/Museum-of-Fine-Arts-Boston-Paintings-of-the-Museum-of-Fine-Arts-Boston-Ananda-Coomaraswamy-the-Daughters-of-Edward-Darley-Boit-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/4a03a02a03a01a00/North-of-Boston-by-Elisabeth-Elo.pdf
    • http://muicuiu.dumb1.com/1a01a09a02a03a09/Kissing-Dirt-by-Nik-Boston.pdf
    • http://muicuiu.dumb1.com/5a02a00a04a08a09/Boston-A-To-Z-by-Thomas-H-O-39-Connor.pdf
    • http://muicuiu.dumb1.com/1a02a09a06a04a06/Boston-Boogie-by-A-J-Converse.pdf
    • http://muicuiu.dumb1.com/3a07a00a03a03a01/Mapping-Boston-by-Alex-Krieger.pdf
    • http://muicuiu.dumb1.com/3a01a01a05a06a05/The-Chimneys-Of-Green-Knowe-by-L-M-Boston.pdf
    • http://muicuiu.dumb1.com/5a06a04a09a06/Adventures-at-Green-Knowe-by-L-M-Boston.pdf
    • http://muicuiu.dumb1.com/2a05a02a06a09a09/The-Boston-Stranglers-by-Susan-Kelly.pdf
    • http://muicuiu.dumb1.com/1a00a08a08a04a07a00/Damen-in-Boston-by-Henry-James.pdf
    • http://muicuiu.dumb1.com/3a07a05a01a02/The-Nightmare-Collection-by-Bruce-Boston.pdf
    • http://muicuiu.dumb1.com/2a07a05a07a01a00/The-Children-of-Green-Knowe-by-L-M-Boston.pdf
    • http://muicuiu.dumb1.com/1a08a02a06a09a06/Crow-Boston-Underworld-1-by-A-Zavarelli.pdf
    • http://muicuiu.dumb1.com/2a07a01a07a06a05/The-Boston-Girl-by-Anita-Diamant.pdf
    • http://muicuiu.dumb1.com/3a09a04a05a09a01/Falling-for-Boston-by-Leslie-Kate.pdf
    • http://muicuiu.dumb1.com/7a05a06a04a