Malicious PDF — malware analysis report

Static analysis result for SHA-256 51b2ee5354fea7c7…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 04:16:15 +01:00 Authoring application: mPDF 5.7
MD5: a87b4d3390f0edee6ab03efdd841a86c SHA-1: 9ed340f3958c0bf7e6c4be054c502ac942cc2d7d SHA-256: 51b2ee5354fea7c7a7677c36f37803d959b020153abe32810313026f3530bf66
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves appear benign, the sheer volume and the critical heuristic firing suggest a malicious intent, possibly for SEO manipulation or as a lure to redirect users to other malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, limiting the analysis of direct payload execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a07a02a01a02a04/Amelia-Rules-Volume-4-When-the-Past-is-a-Present-Amelia-Rules-4-by-Jimmy-Gownley.pdf
    • http://muicuiu.dumb1.com/3a07a01a09a04a01/Amelia-Rules-Volume-1-The-Whole-World-s-Crazy-Amelia-Rules-1-by-Jimmy-Gownley.pdf
    • http://muicuiu.dumb1.com/3a07a02a01a03a00/Amelia-Rules-Volume-2-What-Makes-You-Happy-Amelia-Rules-2-by-Jimmy-Gownley.pdf
    • http://muicuiu.dumb1.com/2a01a02a06a00a00/Amelia-Rules-Volume-3-Superheroes-Amelia-Rules-3-by-Jimmy-Gownley.pdf
    • http://muicuiu.dumb1.com/1a03a02a04a04/Amelia-Lost-The-Life-and-Disappearance-of-Amelia-Earhart-by-Candace-Fleming.pdf
    • http://muicuiu.dumb1.com/2a04a00a02a04a05/Amelia-s-Boredom-Survival-Guide-Amelia-s-Notebooks-5-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/9a06a09a02a06/Amelia-the-Venutons-and-the-Golden-Cage-Amelia-s-Amazing-Space-Adventures-2-by-Evonne-Blanchard.pdf
    • http://muicuiu.dumb1.com/9a08a01a06a01/Amelia-the-Moochins-and-the-Sapphire-Palace-Amelia-s-Amazing-Space-Adventures-1-by-Evonne-Blanchard.pdf
    • http://muicuiu.dumb1.com/3a07a02a03a07a00/Amelia-s-Family-Ties-Amelia-s-Notebooks-9-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/1a07a05a05a02a07/Amelia-s-Guide-to-Gossip-Amelia-s-Notebooks-19-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/7a02a07a04a05a08/Amelia-Takes-Command-Amelia-s-Notebooks-4-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/3a07a02a03a09a03/Amelia-Works-It-Out-Amelia-s-Notebooks-8-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/1a07a08a02a06a09/Amelia-s-Notebook-Amelia-s-Notebooks-1-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/2a04a01a08a07a06/Amelia-Writes-Again-Amelia-s-Notebooks-2-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/2a04a02a01a08a07/The-All-New-Amelia-Amelia-s-Notebooks-7-by-Marissa-Moss.pdf
    • http://muicuiu.dumb1.com/3a05a04a01a05a05/Amelia-s-Destiny-Amelia-2-by-D-G-Torrens.pdf
    • http://muicuiu.dumb1.com/1a03a05a09a00/Our-Only-May-Amelia-May-Amelia-1-by-Jennifer-L-Holm.pdf
    • http://muicuiu.dumb1.com/8a09a08a04a08a08/Early-Monastic-Rules-The-Rules-of-the-Fathers-and-the-Regula-Orientalis-by-C-V-Franklin.pdf
    • http://muicuiu.dumb1.com/4a09a08a00a07a04/The-Customer-Rules-The-39-Essential-Rules-for-Delivering-Sensational-Service-by-Lee-Cockerell.pdf
    • http://muicuiu.dumb1.com/8a07a07a00a01a05/If-Life-Is-a-Game-These-Are-the-Rules-Ten-Rules-for-Being-Human-as-Introduced-in-Chicken-Soup-for-the-Soul-by-Cherie-Carter-Scott.pdf