Malicious PDF — malware analysis report

Static analysis result for SHA-256 50371ce80b93e66f…

MALICIOUS

PDF

21.2 KB Created: 2019-05-07 04:29:24 +01:00 Authoring application: mPDF 5.7
MD5: d7207f1d6d652a9afab6152d34f9cdf3 SHA-1: 2633576b4c2e93643435bb91085347b91e099637 SHA-256: 50371ce80b93e66f3214a51e5299fc78936f6fcabf2a52fa45bef49e1ecbb7d8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself suggests a malicious intent to distribute links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a02a05a05a07/Hero-s-Song-The-Songs-of-Eirren-1-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/3a04a03a03a03a04/East-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/7a06a09a07a08/North-Child-by-Edith-Pattou.pdf
    • http://muicuiu.dumb1.com/4a03a07a06a02a04/Two-Songs-Song-of-Prisoner-amp-Song-of-Malaya-by-Okot-p-39-Bitek.pdf
    • http://muicuiu.dumb1.com/8a06a02a06a02a01/Song-of-Songs-PB-by-Ariel-Bloch.pdf
    • http://muicuiu.dumb1.com/6a07a05a02a08a03/Lamentations-and-the-Song-of-Songs-by-Harvey-Cox.pdf
    • http://muicuiu.dumb1.com/9a09a01a01a02/My-Song-Of-Songs-Solomon-s-Touch-by-Joanna-Hynes.pdf
    • http://muicuiu.dumb1.com/4a05a09a09a01a03/The-Song-of-Songs-Love-Lyrics-from-the-Bible-by-Marcia-Falk.pdf
    • http://muicuiu.dumb1.com/4a09a08a03a06a03/The-Life-of-a-Song-The-fascinating-stories-behind-50-of-the-world-s-best-loved-songs-by-David-Cheal.pdf
    • http://muicuiu.dumb1.com/5a00a08a04a08a05/The-Sun-Has-Burned-My-Skin-A-Modest-Paraphrase-of-Solomon-s-Song-of-Songs-by-Adam-S-Miller.pdf
    • http://muicuiu.dumb1.com/1a01a09a05a02a02a02/Farewell-to-Shulamit-Spatial-and-Social-Diversity-in-the-Song-of-Songs-by-Carsten-L-Wilke.pdf
    • http://muicuiu.dumb1.com/1a01a01a06a01a02a06/Six-Songs-Op-34-No-2-quot-On-Wings-of-Song-quot-by-Felix-Mendelssohn.pdf
    • http://muicuiu.dumb1.com/9a08a05a03a00a04/The-House-of-Mirth-by-Edith-Wharton---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Edith-Wharton-by-Edith-Wharton.pdf
    • http://muicuiu.dumb1.com/1a00a06a06a00a05a02/Som-en-eld-ver-askan-Edith-S-dergrans-Fotografier-by-Edith-S-dergran.pdf
    • http://muicuiu.dumb1.com/8a00a09a05a07a00/Songs-of-Innocence-and-Songs-of-Experience-illustrated-Supreme-Edition-by-William-Blake.pdf
    • http://muicuiu.dumb1.com/9a08a00a09a07/Korean-Folk-Songs-Stars-in-the-Sky-and-Dreams-in-Our-Hearts-14-Sing-Along-Songs-with-the-Audio-CD-included-by-Robert-Choi.pdf
    • http://muicuiu.dumb1.com/4a04a06a02a00a07/Songs-of-Insurrection-The-Dragon-Songs-Saga-1-by-J-C-Kang.pdf
    • http://muicuiu.dumb1.com/1a04a06a06a01a05/Monica-Songs-of-Submission-7-5-Songs-of-Dominance-4-by-C-D-Reiss.pdf
    • http://muicuiu.dumb1.com/1a00a02a00a01a03/The-Tapestry-The-Life-and-Times-of-Francis-and-Edith-Schaeffer-by-Edith-Schaeffer.pdf
    • http://muicuiu.dumb1.com/9a01a05a09a05a02/The-Age-of-Innocence-The-Collected-Works-of-Edith-Wharton---43-Volumes-by-Edith-Wharton.pdf