Malicious PDF — malware analysis report

Static analysis result for SHA-256 493270c4190fb75d…

MALICIOUS

PDF

20.0 KB Created: 2019-05-07 09:10:07 +01:00 Authoring application: mPDF 5.7
MD5: 27fd78c821f6de13b4b0cc046ac48e14 SHA-1: 9c728d608c15afbe7128b33a966ed0efbbe33d93 SHA-256: 493270c4190fb75db2215c6919c5ec76657e43904682ff4d044e76b684a80e31
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 26 links identified. The ML classifier also strongly indicated maliciousness. While the document body is unreadable, the presence of numerous links suggests a redirection or SEO abuse tactic. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a01a00a01a09a07/Nicholas-Everard-Mariner-of-England-2-by-Alexander-Fullerton.pdf
    • http://muicuiu.dumb1.com/5a01a01a01a08a02/From-Psalm-to-Symphony-A-History-of-Music-in-New-England-by-Nicholas-E-Tawa.pdf
    • http://muicuiu.dumb1.com/4a06a03a07a05a08/The-Thieves-of-Threadneedle-Street-The-Incredible-True-Story-of-the-American-Forgers-Who-Nearly-Broke-the-Bank-of-England-by-Nicholas-Booth.pdf
    • http://muicuiu.dumb1.com/4a08a07a07a08a06/The-Captain-s-Courtship-The-Everard-Legacy-2-by-Regina-Scott.pdf
    • http://muicuiu.dumb1.com/2a00a02a01a08a03/The-Rake-s-Redemption-The-Everard-Legacy-3-by-Regina-Scott.pdf
    • http://muicuiu.dumb1.com/1a03a00a04a09a02/A-Portal-in-Time-by-Claire-Fullerton.pdf
    • http://muicuiu.dumb1.com/7a04a00a05a00a06/Quinine-in-Cholera-by-Fullerton-Erskine-B.pdf
    • http://muicuiu.dumb1.com/6a04a08a00a08a02/Hesitations-The-American-Crisis-and-the-War-by-William-Morton-Fullerton.pdf
    • http://muicuiu.dumb1.com/2a02a06a08a01a04/Enraptured-Fullerton-Family-Saga-3-by-Ginger-Voight.pdf
    • http://muicuiu.dumb1.com/8a09a07a02a06a09/England-Glorious-England-Ann-herung-An-Eigenwillige-Verwandte-by-Holger-Ehling.pdf
    • http://muicuiu.dumb1.com/3a03a08a06a05a08/Weird-England-Your-Travel-Guide-to-England-s-Local-Legends-and-Best-Kept-Secrets-by-Matt-Lake.pdf
    • http://muicuiu.dumb1.com/2a06a08a08a03a03/A-Dance-with-Jane-Austen-How-a-Novelist-and-Her-Characters-Went-to-the-Ball-by-Susannah-Fullerton.pdf
    • http://muicuiu.dumb1.com/9a05a05a00a08a02/Fullerton-s-Rangers-A-History-of-the-New-Mexico-Territorial-Mounted-Police-by-Chuck-Hornung.pdf
    • http://muicuiu.dumb1.com/3a09a01a06a05a01/Mariner-s-Hollow-by-F-G-Capitanio.pdf
    • http://muicuiu.dumb1.com/2a03a02a05a09a00/Essential-Sub-Mariner-Vol-1-by-Stan-Lee.pdf
    • http://muicuiu.dumb1.com/7a08a06a00a09a02/The-Baker-s-Dozen-A-Saint-Nicholas-Tale-with-Bonus-Cookie-Recipe-for-St-Nicholas-Christmas-Cookies-by-Aaron-Shepard.pdf
    • http://muicuiu.dumb1.com/2a02a09a02a04a09/The-Postmodern-Mariner-by-Rhys-Hughes.pdf
    • http://muicuiu.dumb1.com/1a00a01a01a05a07a02/The-Beaufort-Dossier-by-David-Mariner.pdf
    • http://muicuiu.dumb1.com/1a01a09a05a06a06a04/Christopher-Columbus-Mariner-by-Samuel-Eliot-Morison.pdf
    • http://muicuiu.dumb1.com/6a00a06a00a03a05/The-Rime-of-the-Ancient-Mariner-by-Samuel-Taylor-Coleridge.pdf
    • http://muicuiu.dumb1.com/2a00a02a01a08a03/The-Rake-s-Redemption-The-Everard-Legacy-3-by-Regina