Malicious PDF — malware analysis report

Static analysis result for SHA-256 500b1255d6adb9d3…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 04:34:15 +01:00 Authoring application: mPDF 5.7
MD5: 8a6acff7c8f56436291e45c4e3f9ef58 SHA-1: 67752a4e2f23d9ac5f8a7e7fbe81ebf57bee93fe SHA-256: 500b1255d6adb9d302fb3c245ecd8e3caa170b18a7b687c537949a89a9013bfb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. While no scripts were extracted, the sheer volume of links and the ML classification suggest a malicious intent, possibly to redirect users to phishing or malware-hosting sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a04a08a05a09a07/City-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/7a04a03a04a02a07/The-Game-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/4a05a02a05a05a04/Silk-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/3a04a05a06a09/Silk-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/3a03a03a04a04a08/Silk-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/8a00a09a08a03a08/Ocean-Sea-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/7a04a03a04a02a06/B-geln-und-in-die-Ferne-schweifen-by-Alessandro-Baricco.pdf
    • http://muicuiu.dumb1.com/4a04a08a03a00a06/The-Day-of-the-Barbarians-The-Battle-That-Led-to-the-Fall-of-the-Roman-Empire-by-Alessandro-Barbero.pdf
    • http://muicuiu.dumb1.com/7a04a03a05a09a00/Silk-by-Alessandro-Baricco-Book-Analysis-Detailed-Summary-Analysis-and-Reading-Guide-BrightSummaries-com-by-Bright-Summaries.pdf
    • http://muicuiu.dumb1.com/4a04a09a02a01a06/Barbarians-Within-the-Gates-of-Rome-A-Study-of-Roman-Military-Policy-and-the-Barbarians-ca-375-425-A-D-by-Thomas-S-Burns.pdf
    • http://muicuiu.dumb1.com/7a02a04a06a03a03/Alessandro-Anselmi-Icone-Per-Il-Terzo-Millennio-by-Alessandro-Anselmi.pdf
    • http://muicuiu.dumb1.com/1a01a04a09a05a05/Barbarians-by-Robert-Carter.pdf
    • http://muicuiu.dumb1.com/1a08a04a01a05a00/Waiting-for-the-Barbarians-by-J-M-Coetzee.pdf
    • http://muicuiu.dumb1.com/9a05a09a05a01a04/Barb-and-the-Barbarians-by-Cynthia-Sax.pdf
    • http://muicuiu.dumb1.com/4a00a08a04a01a03/Barbarians-of-the-Red-Planet-by-Gavin-Chappell.pdf
    • http://muicuiu.dumb1.com/3a08a00a08a08a06/Ice-Ice-Babies-Ice-Planet-Barbarians-6-6-by-Ruby-Dixon.pdf
    • http://muicuiu.dumb1.com/6a05a08a00a07/Barbarians-at-the-Gate-The-Fall-of-RJR-Nabisco-by-Bryan-Burrough.pdf
    • http://muicuiu.dumb1.com/3a03a06a05a06a07/Barbarian-s-Redemption-Ice-Planet-Barbarians-12-by-Ruby-Dixon.pdf
    • http://muicuiu.dumb1.com/2a06a03a00a01a00/Barbarian-s-Taming-Ice-Planet-Barbarians-8-by-Ruby-Dixon.pdf
    • http://muicuiu.dumb1.com/2a07a04a04/Barbarian-s-Prize-Ice-Planet-Barbarians-5-by-Ruby-Dixon.pdf