Malicious PDF — malware analysis report

Static analysis result for SHA-256 52a86e65c6612b5a…

MALICIOUS

PDF

21.8 KB Created: 2019-05-07 02:49:53 +01:00 Authoring application: mPDF 5.7
MD5: 05cf2fffa5215533b43445214cbf9727 SHA-1: 9139b5a4fdcf83a2513603bd15565555183e0de7 SHA-256: 52a86e65c6612b5a6139f0f230be9dd01bc7840781021a62ee18e88d8151a28c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or redirection strategy. The ML_NYX_PDF_MALICIOUS heuristic further supports its malicious nature. While no scripts were extracted, the sheer volume of links points to a coordinated effort to direct users to external content, potentially for SEO manipulation or to host further malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a03a07a02a04a09/Opening-Paul-s-Letters-A-Reader-s-Guide-to-Genre-and-Interpretation-by-Patrick-Gray.pdf
    • http://muicuiu.dumb1.com/5a03a07a04a03a06/Film-Genre-Reader-IV-by-Barry-Keith-Grant.pdf
    • http://muicuiu.dumb1.com/3a06a06a05a05a05/The-Throne-the-Lamb-amp-the-Dragon-A-Reader-s-Guide-to-the-Book-of-Revelation-by-Paul-Spilsbury.pdf
    • http://muicuiu.dumb1.com/5a03a07a03a07a02/Animation-Genre-and-Authorship-by-Paul-Wells.pdf
    • http://muicuiu.dumb1.com/9a01a06a05a05a07/The-Horror-Genre-From-Beelzebub-to-Blair-Witch-by-Paul-Wells.pdf
    • http://muicuiu.dumb1.com/5a03a07a03a01a00/Historical-Fiction-II-A-Guide-to-the-Genre-by-Sarah-L-Johnson.pdf
    • http://muicuiu.dumb1.com/7a03a08a03a00a07/Patrick-S-skinds-Roman-Das-Parfum-Stichworte-zur-Interpretation-by-Nikolaj-Aaron.pdf
    • http://muicuiu.dumb1.com/3a03a03a01a07a07/The-Reader-s-Digest-Do-It-Yourself-Guide-to-Preventing-Costly-HomeRepairs-Over-19-000-Easy-Hints-amp-Tips-by-Reader-39-s-Digest-Association.pdf
    • http://muicuiu.dumb1.com/4a04a07a00a05a02/Unsolved-Mysteries-of-History-An-Eye-Opening-Investigation-Into-the-Most-Baffling-Events-of-All-Time-by-Paul-Aron.pdf
    • http://muicuiu.dumb1.com/1a01a06a01a08a07a01/Conferring-The-Keystone-of-Reader-s-Workshop-by-Patrick-A-Allen.pdf
    • http://muicuiu.dumb1.com/6a07a03a04a00a09/Freud-and-Philosophy-An-Essay-on-Interpretation-by-Paul-Ric-ur.pdf
    • http://muicuiu.dumb1.com/8a00a03a04a04a04/Begegnung-Mit-Paul-Celan-Erinnerung-Und-Interpretation-by-Edith-Silbermann.pdf
    • http://muicuiu.dumb1.com/8a08a02a08a00a08/Opening-Science-The-Evolving-Guide-on-How-the-Internet-Is-Changing-Research-Collaboration-and-Scholarly-Publishing-by-S-nke-Bartling.pdf
    • http://muicuiu.dumb1.com/1a01a02a07a00a00a01/Opening-Science-The-Evolving-Guide-on-How-the-Internet-Is-Changing-Research-Collaboration-and-Scholarly-Publishing-by-Soenke-Bartling.pdf
    • http://muicuiu.dumb1.com/6a07a03a06a02a08/Interdisciplinary-Interpretation-Paul-Ricoeur-and-the-Hermeneutics-of-Theology-and-Science-by-Kenneth-A-Reynhout.pdf
    • http://muicuiu.dumb1.com/2a02a02a05a00a03/Letters-to-God-From-the-Major-Motion-Picture-by-Patrick-Doughtie.pdf
    • http://muicuiu.dumb1.com/4a01a03a07a09a04/The-Curious-Dreamer-s-Practical-Guide-to-Dream-Interpretation-by-Nancy-Wagaman.pdf
    • http://muicuiu.dumb1.com/4a07a06a05a04a01/The-Lincoln-Reader-by-Paul-M-Angle.pdf
    • http://muicuiu.dumb1.com/5a08a00a02a08a05/The-Reader-on-the-6-27-by-Jean-Paul-Didierlaurent.pdf
    • http://muicuiu.dumb1.com/2a06a06a06a04a05/The-Reader-on-the-6-27-by-Jean-Paul-Didierlaurent.pdf
    • http://muicuiu.dumb1.com/3a03a0