Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e8891ab98d23aa7…

MALICIOUS

PDF

21.7 KB Created: 2019-04-30 03:54:43 +01:00 Authoring application: mPDF 5.7
MD5: a64c4a341a20fdc6ec54d7a63604a298 SHA-1: 7c8bb41eebcbdd18621ac063e87daca5eebb1ee8 SHA-256: 4e8891ab98d23aa79fdc0d6af59c2d2930c38951493763c216c2d02029542892
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the heuristic suggests the document's purpose is to redirect users to a multitude of external sites, likely for SEO poisoning or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a02a01a02a03/Bluff-Bluster-Lies-and-Spies-The-Lincoln-Foreign-Policy-1861-1865-by-David-Perry.pdf
    • http://muicuiu.dumb1.com/2a05a06a09a05a01/21-Lies-They-Tell-You-About-American-Foreign-Policy-by-Brett-Saxon-Morris.pdf
    • http://muicuiu.dumb1.com/6a09a06a04a06a00/Japan-s-Foreign-Policy-1945-2003-The-Quest-for-a-Proactive-Policy-by-Kazuhiko-Togo.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a04a07/The-Civil-War-Day-By-Day-An-Almanac-1861-1865-by-E-B-Long.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a08a00/The-Image-of-War-1861-1865-Volume-1-Shadows-of-the-Storm-by-William-C-Davis.pdf
    • http://muicuiu.dumb1.com/6a06a07a04a07/A-Chain-of-Thunder-Civil-War-1861-1865-Western-Theater-2-by-Jeff-Shaara.pdf
    • http://muicuiu.dumb1.com/6a08a01a05a08/A-Blaze-of-Glory-Civil-War-1861-1865-Western-Theater-1-by-Jeff-Shaara.pdf
    • http://muicuiu.dumb1.com/2a03a03a02a04/The-Organization-and-Administration-of-the-Union-Army-1861-1865-Volume-I-by-Fred-Albert-Shannon.pdf
    • http://muicuiu.dumb1.com/2a03a03a02a06/The-Organization-and-Administration-of-the-Union-Army-1861-1865-Volume-II-by-Fred-Albert-Shannon.pdf
    • http://muicuiu.dumb1.com/2a04a07a03a00a03/The-Sacred-Moon-Tree-Being-the-True-Account-of-the-Trials-and-Adventures-of-Phoebe-Sands-in-the-Great-War-Between-the-States-1861-1865-by-Laura-Jan-Shore.pdf
    • http://muicuiu.dumb1.com/5a00a09a01a04a08/The-Anatomy-of-the-Confederate-Congress-A-Study-of-the-Influence-of-Member-Characteristics-on-Legislative-Voting-Behavior-1861-1865-by-Thomas-Benjamin-Alexander.pdf
    • http://muicuiu.dumb1.com/3a02a04a08a03a03/I-Thought-My-Soul-Would-Rise-and-Fly-The-Diary-of-Patsy-a-Freed-Girl-Mars-Bluff-South-Carolina-1865-Dear-America-Series-by-Joyce-Hansen.pdf
    • http://muicuiu.dumb1.com/1a05a04a03a00a08/A-Foreign-Policy-for-Americans-by-Robert-A-Taft.pdf
    • http://muicuiu.dumb1.com/2a01a00a03a04a05/The-Israel-Lobby-and-U-S-Foreign-Policy-by-John-J-Mearsheimer.pdf
    • http://muicuiu.dumb1.com/1a01a07a05a07a08a01/How-American-Foreign-Policy-is-Made-by-John-W-Spanier.pdf
    • http://muicuiu.dumb1.com/5a08a01a06a04a06/Australian-Foreign-Policy-in-the-Age-of-Terror-by-Carl-Ungerer.pdf
    • http://muicuiu.dumb1.com/7a05a00a05a07a08/Bridging-the-Foreign-Policy-Divide-by-Chollet-Derek.pdf
    • http://muicuiu.dumb1.com/2a00a02a02a04a09/The-Illusion-Of-Peace-Foreign-Policy-in-the-Nixon-Years-by-Tad-Szulc.pdf
    • http://muicuiu.dumb1.com/1a00a01a00a04a02a09/Before-amp-After-U-S-Foreign-Policy-and-the-September-11th-Crisis-by-Phyllis-Bennis.pdf
    • http://muicuiu.dumb1.com/5a01a07a01a09a09/A-True-History-of-the-Assassination-of-Abraham-Lincoln-and-the-Conspiracy-Of-1865-by-Louis-J-Weichmann.pdf
    • http://muicuiu.dumb1.com/2a03a03a02a06/The-Organization-and-Administration-of-the-Union-Army-1861-1865-Volume-II-by-Fred-Al