Malicious PDF — malware analysis report

Static analysis result for SHA-256 500d9a7acd95d0bc…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 04:54:38 +01:00 Authoring application: mPDF 5.7
MD5: f5b7fe7daf036406c65be35f0acff096 SHA-1: a94ba78c7d67d45e26af9e96f0a064d9ba4acc60 SHA-256: 500d9a7acd95d0bc8cb10bbbcd9313f0d08f83c1d29bc531ef3143b3f58a4a05
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to various external websites. The ML classifier also strongly indicated maliciousness. While the document body is unreadable, the primary attack vector appears to be a link farm designed to drive traffic to potentially malicious content hosted on the 'dumb1.com' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a07a01a00a05/Faith-A-Journey-For-All-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/3a05a05a01a05a01/Faith-A-Journey-For-All-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/1a06a01a08a02a04/Keeping-Faith-Memoirs-of-a-President-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/1a08a05a08a06a00/Palestine-Peace-Not-Apartheid-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/1a06a01a08a02a08/White-House-Diary-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/5a00a01a07a06a01/Christmas-in-Plains-Memories-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/4a04a07a08a05a01/Talking-Peace-A-Vision-for-the-Next-Generation-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/2a07a04a01a06a08/Talking-Peace-A-Vision-for-the-Next-Generation-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/1a06a01a08a02a00/An-Hour-Before-Daylight-Memories-of-a-Rural-Boyhood-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/1a06a01a08a02a03/Turning-Point-A-Candidate-a-State-and-a-Nation-Come-of-Age-by-Jimmy-Carter.pdf
    • http://muicuiu.dumb1.com/5a00a07a02a07a06/Jimmy-Carter-as-President-Leadership-and-the-Politics-of-the-Public-Good-by-Erwin-C-Hargrove.pdf
    • http://muicuiu.dumb1.com/3a07a05a07a03a06/The-Case-Against-Israel-s-Enemies-Exposing-Jimmy-Carter-and-Others-Who-Stand-in-the-Way-of-Peace-by-Alan-M-Dershowitz.pdf
    • http://muicuiu.dumb1.com/8a02a06a09a01a09/Weed-Man-The-Remarkable-Journey-of-Jimmy-Divine-by-John-McCaslin.pdf
    • http://muicuiu.dumb1.com/2a03a07a00a02a02/Bella-Abzug-How-One-Tough-Broad-from-the-Bronx-Fought-Jim-Crow-and-Joe-McCarthy-Pissed-Off-Jimmy-Carter-Battled-for-the-Rights-of-Women-and-Workers-Planet-and-Shook-Up-Politics-Along-the-Way-by-Suzanne-Braun-Levine.pdf
    • http://muicuiu.dumb1.com/1a01a04a03a04a00a08/-quot-What-the-Heck-Are-You-Up-To-Mr-President-quot-Jimmy-Carter-America-s-quot-Malaise-quot-and-the-Speech-that-Should-Have-Changed-the-Country-by-Kevin-Mattson.pdf
    • http://muicuiu.dumb1.com/2a00a08a05a08a05/Journey-to-the-Centre-of-My-Brain-by-James-Carter.pdf
    • http://muicuiu.dumb1.com/3a00a06a06a08a05/Hurricane-The-Miraculous-Journey-of-Rubin-Carter-by-James-S-Hirsch.pdf
    • http://muicuiu.dumb1.com/1a02a02a06a04a00/A-Journey-of-Faith-Son-of-Mine-2-by-Karen-Malena.pdf
    • http://muicuiu.dumb1.com/1a00a04a06a08a00a03/Abraham-Kuyper-His-Early-Journey-Of-Faith-by-G-Puchinger.pdf
    • http://muicuiu.dumb1.com/4a02a03a09a02a00/Refractions-A-Journey-of-Faith-Art-and-Culture-by-Makoto-Fujimura.pdf
    • http://muicuiu.dumb1.com/5a00a07a02a07a06/Jimmy-Carter-as-Pre