Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f3e30151d446573…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 08:55:34 +01:00 Authoring application: mPDF 5.7
MD5: 7c31e0c83d41cf933d24618a73eebab0 SHA-1: e0e2056ef3b6eb741b0c3b7b23acdd220122c17f SHA-256: 4f3e30151d446573b818dcb171bb3c4303424ac25505d6ad571131eb57c302ef
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the specific content of these linked PDFs is benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to host further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a08a01a04a03a00/Conan-the-Conqueror-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/7a00a04a06a06a02/Conan-The-Freebooter-Conan-3-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/1a06a04a02a02a07/The-Conan-Chronicles-Volume-1-The-People-of-the-Black-Circle-The-Conan-Chronicles-1-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/1a06a03a04a05a07/The-Essential-Conan-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/3a04a09a00a08a04/Conan-the-Barbarian-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/7a00a04a06a09a00/Conan-the-Avenger-Book-10-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/7a00a04a07a09a01/Conan-the-Barbarian-The-Complete-Collection-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/3a03a05a06a00a08/Conan-the-Barbarian-The-Stories-that-Inspired-the-Movie-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/2a08a09a06a03a01/Waterfront-Fists-And-Others-The-Collected-Fight-Stories-Of-Robert-E-Howard-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/4a02a08a08a09a01/The-Conqueror-A-Novel-of-William-the-Conqueror-the-Bastard-Son-Who-Overpowered-a-Kingdom-and-the-Woman-Who-Melted-His-Heart-by-Georgette-Heyer.pdf
    • http://muicuiu.dumb1.com/2a02a01a04a06a08/Conqueror-A-Novel-of-Kublai-Khan-Conqueror-5-by-Conn-Iggulden.pdf
    • http://muicuiu.dumb1.com/3a00a05a06a04a07/Almuric-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/4a06a02a06a07a05/The-Dream-Snake-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/2a08a09a02a05a01/The-Slithering-Shadow-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/3a01a05a09a07a09/Sword-Woman-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/9a05a07a07a00/Marchers-of-Valhalla-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/2a08a09a02a06a03/Gods-of-the-North-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/2a08a09a02a05a07/Shadows-In-The-Moonlight-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/2a04a07a04a09/Pigeons-from-Hell-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/1a00a00a08a01a08/The-Sowers-of-the-Thunder-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/4a02a08a08a09a01/The-Conqueror-A-Novel-of-William-the-Con