Malicious PDF — malware analysis report

Static analysis result for SHA-256 5267bcde4b701f10…

MALICIOUS

PDF

19.4 KB Created: 2019-05-02 01:31:03 +01:00 Authoring application: mPDF 5.7
MD5: 00d6329496e425ea7c1fab0f5e55faba SHA-1: 1b157996fa93ed44b24eb00fce832dc13da75f13 SHA-256: 5267bcde4b701f10ea581c192f39956a3d8ccb31571e56446796b1d3b20457d5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to serve as a lure for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1
    • http://muicuiu.dumb1.com/3a04a04a05a05a00/Mister-Darcy-s-Dogs-A-Mister-Darcy-Series-Comedic-Mystery-1-by-Barbara-Silkstone.pdf
    • http://muicuiu.dumb1.com/3a07a01a08a06a07/The-Adventures-of-Mister-Bubble---Mister-Bubble-and-the-Greedy-Triplets-Colour-It-Yourself-Edition-by-Luke-Mathius-Harlow.pdf
    • http://muicuiu.dumb1.com/9a09a08a08a07/Mister-Sandman-by-Barbara-Gowdy.pdf
    • http://muicuiu.dumb1.com/1a01a00a08a00a04a01/-Hallo-Mister-Gott-hier-spricht-Anna-Anna-schreibt-an-Mister-Gott-Limitierte-Sonderausgabe-Zwei-Romane-by-Fynn.pdf
    • http://muicuiu.dumb1.com/5a09a00a08a06a00/Handbook-for-Hot-Witches-Dame-Darcy-s-Illustrated-Guide-to-Magic-Love-and-Creativity-by-Dame-Darcy.pdf
    • http://muicuiu.dumb1.com/1a06a04a06a01a02/Jade-Darcy-and-the-Affair-of-Honor-The-Rehumanization-of-Jade-Darcy-1-by-Stephen-Goldin.pdf
    • http://muicuiu.dumb1.com/1a04a06a09a02a09/Darcy-amp-Elizabeth-Nights-and-Days-at-Pemberley-Darcy-amp-Elizabeth-2-by-Linda-Berdoll.pdf
    • http://muicuiu.dumb1.com/7a05a01a02a08a05/The-Inseparable-Mr-and-Mrs-Darcy-Meryton-Mystery-3-by-Jennifer-Joy.pdf
    • http://muicuiu.dumb1.com/1a08a02a08a04/Matinicus----An-Island-Mystery-by-Darcy-Scott.pdf
    • http://muicuiu.dumb1.com/2a05a08a01a04a00/Grade-A-Stupid-The-Darcy-Walker-Series-1-by-A-J-Lape.pdf
    • http://muicuiu.dumb1.com/2a05a02a01a07a03/Dressed-to-Keel-A-Darcy-Cavanaugh-Mystery-1-by-Candy-Calvert.pdf
    • http://muicuiu.dumb1.com/2a08a02a03a09a02/The-Netherfield-Affair-A-Dark-Darcy-Mystery-by-Penelope-Swan.pdf
    • http://muicuiu.dumb1.com/4a06a09a05/Mr-Match-Mister-5-by-J-A-Huss.pdf
    • http://muicuiu.dumb1.com/2a03a06a07a05/Mister-Miracle-Vol-1-by-Tom-King.pdf
    • http://muicuiu.dumb1.com/3a05a09a06a01/Mister-Pip-by-Lloyd-Jones.pdf
    • http://muicuiu.dumb1.com/4a00a08a04a08a01/Mister-Socky-by-Tim-Miller.pdf
    • http://muicuiu.dumb1.com/4a07a06a04a07a03/Mister-Ed-and-Me-and-More-by-Alan-Young.pdf
    • http://muicuiu.dumb1.com/6a05a07a03a08a03/Mister-B-Up-in-the-air-Saison-4-by-R-K-Lilley.pdf
    • http://muicuiu.dumb1.com/1a01a04a02a02a05a08/Mister-Dynamit-524-Teufelskreis-by-C-H-Guenter.pdf
    • http://muicuiu.dumb1.com/4a08a07a04a07a07/Mister-Wrong-by-Nicole-Williams.pdf