Malicious PDF — malware analysis report

Static analysis result for SHA-256 4dca2a3c46516e14…

MALICIOUS

PDF

17.4 KB Created: 2019-05-07 02:54:38 +01:00 Authoring application: mPDF 5.7
MD5: 72e16b4b9c89f1f6a1840ffd8dfe2082 SHA-1: 90756c89080c8ae4c2277977e9334e9b98ed09dc SHA-256: 4dca2a3c46516e14ab947e110475b6d1b054b25f7d8fb6c39f51e107c5aa5baf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and embedded URLs suggest a content-luring or redirection attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a07a05a08a02a09/Bonhoeffer---Widerstand-und-Ergebung-by-Mario-Hartmann.pdf
    • http://muicuiu.dumb1.com/8a07a05a07a02a05/Widerstand-Gegen-Die-NS-Besatzung-in-Europa-Albanischer-Widerstand-Im-Zweiten-Weltkrieg-Belgischer-Widerstand-1940-1945-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/3a07a04a08a07a02/Arthurian-Romances-Tales-and-Lyric-Poetry-The-Complete-Works-of-Hartmann-Von-Aue-by-Hartmann-von-Aue.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a01a02a06/Voices-in-the-Night-The-Prison-Poems-of-Dietrich-Bonhoeffer-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/1a00a06a01a09a02a01/Wonder-of-Wonders-Christmas-with-Dietrich-Bonhoeffer-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/9a06a08a01a03a09/The-Philosophy-of-Nicolai-Hartmann-by-Nicolai-Hartmann-Society-International-C.pdf
    • http://muicuiu.dumb1.com/4a08a03a09a03a00/Lustvolle-Ergebung---Shadows-of-Love-by-Lilly-Gr-nberg.pdf
    • http://muicuiu.dumb1.com/8a08a00a08a06a07/Mario-Botta---Centre-D-rrenmatt-Neuch-tel-by-Mario-Botta.pdf
    • http://muicuiu.dumb1.com/3a04a01a03a05/The-Cost-of-Discipleship-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/4a05a02a07a00a07/Christmas-Sermons-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/1a03a08a02a09a06/Sanctorum-Communio-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/4a05a00a08a00a01/A-Testament-To-Freedom-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/8a07a05a08a06a01/Der-K-A-I-N--Widerstand-by-Bettina-Petrik.pdf
    • http://muicuiu.dumb1.com/1a00a06a01a09a07a00/Love-Letters-from-Cell-92-by-Dietrich-Bonhoeffer.pdf
    • http://muicuiu.dumb1.com/8a07a05a06a06a09/Fugung-Und-Widerstand-by-Rudolf-Henz.pdf
    • http://muicuiu.dumb1.com/1a01a03a09a02a09a01/Im-Judischen-Widerstand-by-Aleks-Faitelson.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a01a01a06/Dietrich-Bonhoeffer-Reality-and-Resistance-by-Larry-L-Rasmussen.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a01a02a07/The-Life-and-Death-of-Dietrich-Bonhoeffer-by-Mary-Bosanquet.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a01a02a04/Dietrich-Bonhoeffer-s-Christmas-Sermons-by-Edwin-H-Robertson.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a01a02a09/The-Twisted-Cross-and-Dietrich-Bonhoeffer-by-Thomas-E-Patten.pdf