Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f91959f2ef4aad4…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 00:02:16 +01:00 Authoring application: mPDF 5.7
MD5: b9d4c157bcc596e76235ecd1040c241d SHA-1: 604c1c793d5d6b90917ea32bbab8b50c4295b643 SHA-256: 4f91959f2ef4aad4ae37d483a767a32c218cb6787757ed45b1da6de2d1619e48
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely SEO spam or a redirection to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a07a07a01a00a08/A-Ghost-of-a-Chance-A-Viola-Valentine-Mystery-Book-1-by-Cherie-Claire.pdf
    • http://muicuiu.dumb1.com/2a06a01a01a04a09/The-Accidental-Call-Girl-Accidental-1-by-Portia-Da-Costa.pdf
    • http://muicuiu.dumb1.com/3a05a04a02a08a05/The-Accidental-Movie-Star-Accidental-1-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/4a05a01a08a03a09/Accidental-Rock-Star-Accidental-4-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/1a09a09a01a09a05/Accidental-Action-Star-Accidental-3-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a05a05/The-Accidental-Movie-Star-Accidental-1-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/4a03a07a09a08a07/The-Accidental-TV-Star-Accidental-2-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/1a09a09a00a05a04/Accidental-Billionaire-Accidental-5-by-Emily-Evans.pdf
    • http://muicuiu.dumb1.com/9a00a09a03a04a01/The-Complete-Gillian-Flynn-Gone-Girl-Dark-Places-Sharp-Objects-by-Gillian-Flynn.pdf
    • http://muicuiu.dumb1.com/2a00a08a03a00a06/The-Novels-of-Gillian-Flynn-Sharp-Objects-Dark-Places-by-Gillian-Flynn.pdf
    • http://muicuiu.dumb1.com/4a03a05a06a05a01/Fry-Bacon-Add-Onions-The-Valentine-Family-amp-Friends-Cookbook-by-Kathleen-Valentine.pdf
    • http://muicuiu.dumb1.com/9a02a06a02a09a08/Best-Valentine-s-Day-Comeplete-Guide-For-a-Perfect-Valentine-s-Day-by-Duby-Nevo.pdf
    • http://muicuiu.dumb1.com/3a04a08a02a08a05/A-Town-Called-Valentine-Valentine-Valley-1-by-Emma-Cane.pdf
    • http://muicuiu.dumb1.com/6a09a06a01a04a06/Valentine-Pontifex-Lord-Valentine-3-by-Robert-Silverberg.pdf
    • http://muicuiu.dumb1.com/3a08a08a02a05a06/Flight-of-a-Valentine-The-Valentine-Series-by-Angela-Bradley.pdf
    • http://muicuiu.dumb1.com/7a04a04a05a02a08/Yvan-a-Claire---Yvan-an-Claire---Yvan-to-Claire-Studien-Zur-Thematik-Und-Symbolik-Der--Clairelyrik--Yvan-Golls-by-Pierre-Georges-Pouthier.pdf
    • http://muicuiu.dumb1.com/9a03a00a01a01a02/Hallo-Claire---I-miss-you-Marie-amp-Claire-1-by-Renate-Ahrens.pdf
    • http://muicuiu.dumb1.com/4a09a03a06a03a08/I-Love-Claire-Claire-Everett-3-by-Tracey-Bateman.pdf
    • http://muicuiu.dumb1.com/5a00a04a00a09a06/Lord-Valentine-s-Castle-Majipoor-Lord-Valentine-1-by-Robert-Silverberg.pdf
    • http://muicuiu.dumb1.com/2a05a00a00a08/Lord-Valentine-s-Castle-Lord-Valentine-1-by-Robert-Silverberg.pdf
    • http://muicuiu.dumb1.com/4a03a05a06a05a01/