Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f31a41288dcf8b7…

MALICIOUS

PDF

20.0 KB Created: 2019-05-03 17:11:00 +01:00 Authoring application: mPDF 5.7
MD5: e7035f029fb21238a70b28b64a64633f SHA-1: 93e64526f9d5c4f9eabb0fd4f8b9284cc3b85967 SHA-256: 4f31a41288dcf8b7dc730b8742232853d2903a89b7090ac52431fdb9e7bbc4e7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a07a02a02a06a01/Foundations-in-Urban-Planning---Hegemann-amp-Peets-The-American-Vitruvius-An-Architects-Handbook-of-Civic-Art-by-Werner-Hegemann.pdf
    • http://muicuiu.dumb1.com/1a00a07a02a02a05a02/Hegemann-and-Peets-American-Vitruvius-by-W-Hegemann.pdf
    • http://muicuiu.dumb1.com/2a08a05a00a05a04/Trading-in-Danger-Vatta-s-War-1-by-Elizabeth-Moon.pdf
    • http://muicuiu.dumb1.com/9a07a08a07a01a09/Building-Winning-Algorithmic-Trading-Systems-A-Trader-s-Journey-From-Data-Mining-to-Monte-Carlo-Simulation-to-Live-Trading-by-Kevin-Davey.pdf
    • http://muicuiu.dumb1.com/5a01a00a06a04a06/Opening-the-Island-Poems-by-Anne-Compton-by-Anne-Compton.pdf
    • http://muicuiu.dumb1.com/1a04a06a09a02a09/Darcy-amp-Elizabeth-Nights-and-Days-at-Pemberley-Darcy-amp-Elizabeth-2-by-Linda-Berdoll.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a03a02a06/Frank-Begay---Skalpjagd-Ein-Navaho-Cop-bei-den-Sioux-by-Ulrich-Wissmann.pdf
    • http://muicuiu.dumb1.com/3a08a06a08a07a00/A-Few-Days-in-the-Country-And-Other-Stories-by-Elizabeth-Harrower.pdf
    • http://muicuiu.dumb1.com/3a05a02a03a01a04/How-To-Lose-A-Lord-In-10-Days-Or-Less-Tricks-Of-The-Ton-3-by-Elizabeth-Michels.pdf
    • http://muicuiu.dumb1.com/1a00a00a03a07a06/Gentlemen-and-Jesuits-Quests-for-Glory-and-Adventure-in-the-Early-Days-of-New-France-by-Elizabeth-Jones.pdf
    • http://muicuiu.dumb1.com/1a01a01a02a03a08a00/Eighty-Days-Nellie-Bly-and-Elizabeth-Bisland-s-History-Making-Race-Around-the-World-by-Matthew-Goodman.pdf
    • http://muicuiu.dumb1.com/1a00a07a02a04a00a03/100-Tipps-zum-Abnehmen-by-Arina-Hegemann.pdf
    • http://muicuiu.dumb1.com/8a04a03a06a07a00/Brink-by-Shanna-Compton.pdf
    • http://muicuiu.dumb1.com/2a07a04a08a06/The-Steel-Crocodile-by-D-G-Compton.pdf
    • http://muicuiu.dumb1.com/3a00a06a04a08a05/Exodus-Lost-by-S-C-Compton.pdf
    • http://muicuiu.dumb1.com/1a07a08a02a01a05/The-Counting-Downers-by-A-J-Compton.pdf
    • http://muicuiu.dumb1.com/1a00a07a02a02a05a04/Upgrading-of-Wastewater-Treatment-Plants-1993-by-Hegemann.pdf
    • http://muicuiu.dumb1.com/3a03a01a01a05a05/The-Rival-Monster-by-Compton-Mackenzie.pdf
    • http://muicuiu.dumb1.com/6a08a08a09a02a00/Rescuing-Olivia-by-Julie-Compton.pdf
    • http://muicuiu.dumb1.com/5a00a01a07a00a01/The-Goodnight-Trail-by-Ralph-Compton.pdf