Malicious PDF — malware analysis report

Static analysis result for SHA-256 503f2184bf014d91…

MALICIOUS

PDF

22.9 KB Created: 2019-04-30 04:00:44 +01:00 Authoring application: mPDF 5.7
MD5: 2bcc4c0fe1fd7e1a29be372d7259e33b SHA-1: cdb29811d7600efcd1b97938270671c666f55855 SHA-256: 503f2184bf014d91d83c6ecbc0fead031d7e1efc5e752dff424c6fe1ea781e11
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body text is heavily obfuscated, the presence of numerous links suggests a redirection or SEO poisoning attack. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of this PDF. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a07a05a03a06a04/How-to-Live-A-Life-of-Montaigne-in-one-question-and-twenty-attempts-at-an-answer-by-Sarah-Bakewell.pdf
    • http://muicuiu.dumb1.com/2a08a05a01a08/The-Answer-To-Your-Question-by-Paulette-Bates-Alden.pdf
    • http://muicuiu.dumb1.com/4a03a05a09a01a09/The-Answer-To-Your-Question-by-Paulette-Bates-Alden.pdf
    • http://muicuiu.dumb1.com/2a08a02a02/At-the-Existentialist-Caf-Freedom-Being-and-Apricot-Cocktails-by-Sarah-Bakewell.pdf
    • http://muicuiu.dumb1.com/4a04a07a02a05a01/The-God-Particle-If-the-Universe-Is-the-Answer-What-Is-the-Question-by-Leon-M-Lederman.pdf
    • http://muicuiu.dumb1.com/3a01a03a01a09a01/Why-The-Best-Ever-Question-and-Answer-Book-about-Nature-Science-and-the-World-around-You-by-Catherine-Ripley.pdf
    • http://muicuiu.dumb1.com/2a06a08a06a05a03/Be-a-Unicorn-and-Live-Life-on-the-Bright-Side-by-Sarah-Ford.pdf
    • http://muicuiu.dumb1.com/1a00a00a03a04a06a07/Wie-soll-ich-leben-oder-Das-Leben-Montaignes-in-einer-Frage-und-zwanzig-Antworten-by-Sarah-Bakewell.pdf
    • http://muicuiu.dumb1.com/5a04a09a06a09a03/Montaigne-Selections-From-His-Writings-With-an-Introductory-Essay-by-Andre-Gide-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/5a09a07a05a02a04/Montaigne-s-Essays-and-Selected-Writings-A-Bilingual-Edition-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/6a04a05a08a05a07/Essays-of-Michael-Seigneur-De-Montaigne-with-Marginal-Notes-and-Quotations-of-the-cited-Authors-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a07a03a01/The-Transnationalized-Social-Question-Migration-and-the-Politics-of-Social-Inequalities-in-the-Twenty-First-Century-by-Thomas-Faist.pdf
    • http://muicuiu.dumb1.com/5a09a07a03a08a04/The-Essays-of-Montaigne---Volume-02-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/5a09a07a05a02a05/The-Essays-of-Montaigne---Volume-17-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/8a01a07a00a05a09/The-Essays-of-Montaigne-1893-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/5a09a07a05a09a03/The-Essays-of-Montaigne---Volume-18-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/5a09a07a05a08a06/The-Essays-of-Montaigne---Volume-12-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/5a08a01a09a03/The-Complete-Essays-of-Montaigne-by-Michel-de-Montaigne.pdf
    • http://muicuiu.dumb1.com/6a06a07a09a08a08/The-Thriving-Introvert-Embrace-the-Gift-of-Introversion-and-Live-the-Life-You-Were-Meant-to-Live-Free-Workbook-Included-by-Thibaut-Meurisse.pdf
    • http://muicuiu.dumb1.com/3a00a05a05a02a07/Twenty-Boy-Summer-by-Sarah-Ockler.pdf
    • http://muicuiu.dumb1.com/3a01a03a01a09a01/Why-The-Best-Ever-Question-and-Answer-Book-about-Nature-Science-and-the-World-around-You-by-Catherine-Ri