Malicious PDF — malware analysis report

Static analysis result for SHA-256 552b5e6ed561ab91…

MALICIOUS

PDF

21.1 KB Created: 2019-05-03 06:27:46 +01:00 Authoring application: mPDF 5.7
MD5: 12c1d0b6d397194a84a572f1edf5794a SHA-1: b525dde5c67dad47960306d5d096abf97bfea6e2 SHA-256: 552b5e6ed561ab91fbf6309544031554bc52ac8d07a2e679449ece9b5888e337
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9447

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a04a07a06a05a06/Night-Sky-With-the-Naked-Eye-Explore-Identify-and-Observe-the-Planets-Stars-Space-Stations-and-Satellites-without-Special-Equipment-by-Bob-King.pdf
    • http://muicuiu.dumb1.com/3a04a01a08a04a00/Pollinators-of-Native-Plants-Attract-Observe-and-Identify-Pollinators-and-Beneficial-Insects-with-Native-Plants-by-Heather-N-Holm.pdf
    • http://muicuiu.dumb1.com/5a00a07a02a00a07/America-s-Space-Sentinels-DSP-Satellites-and-National-Security-by-Jeffrey-T-Richelson.pdf
    • http://muicuiu.dumb1.com/3a09a09a06a03a09/The-Naked-King-Naked-Nobility-7-by-Sally-MacKenzie.pdf
    • http://muicuiu.dumb1.com/5a09a06a07/The-Space-Between-the-Stars-by-Anne-Corlett.pdf
    • http://muicuiu.dumb1.com/1a06a02a07a08a06/The-Riven-Stars-Mapped-Space-3-by-Stephen-Renneberg.pdf
    • http://muicuiu.dumb1.com/2a00a04a02a07a09/Wishing-Stars-Space-Opera-Fairytales-by-Nenia-Campbell.pdf
    • http://muicuiu.dumb1.com/4a07a00a02a03/The-Naked-God-Night-s-Dawn-3-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/4a02a02a02a08a06/My-Dream-of-Stars-From-Daughter-of-Iran-to-Space-Pioneer-by-Anousheh-Ansari.pdf
    • http://muicuiu.dumb1.com/3a01a03a06a04a00/Short-Elementary-Level-Stories-Bundle-2-3-Short-Stories-in-1-Ebook-Books-about-Santa-mystery-space-animals-planets-family-Perfect-for-kids-under-10-learning-to-read-by-Betty-J-Byers.pdf
    • http://muicuiu.dumb1.com/3a07a04a05a01a00/Martin-King-and-the-Space-Angels-Martin-King-1-by-James-Thorpe.pdf
    • http://muicuiu.dumb1.com/6a00a00a00a01a04/Sun-Moon-amp-Planets-Learn-about-the-Sun-and-Moon-and-how-to-locate-the-planets-Astronomy-1-by-Tom-Vandamme.pdf
    • http://muicuiu.dumb1.com/2a02a00a04a06a00/Space-Is-Just-a-Starry-Night-by-Tanith-Lee.pdf
    • http://muicuiu.dumb1.com/7a07a08a09a04a02/Yuri-s-Day-A-Road-To-The-Stars-by-Andrew--King.pdf
    • http://muicuiu.dumb1.com/4a09a00a04a00a09/Full-Dark-No-Stars-by-Stephen-King.pdf
    • http://muicuiu.dumb1.com/5a00a02a09a04a09/Sovereign-of-Stars-The-She-King-3-by-Libbie-Hawker.pdf
    • http://muicuiu.dumb1.com/3a03a06a01a02a02/Night-of-a-Thousand-Stars-by-Deanna-Raybourn.pdf
    • http://muicuiu.dumb1.com/4a05a07a01a07a04/King-s-Dragon-Crown-of-Stars-1-by-Kate-Elliott.pdf
    • http://muicuiu.dumb1.com/3a02a01a01a04a03/Ancestral-Night-White-Space-1-by-Elizabeth-Bear.pdf
    • http://muicuiu.dumb1.com/3a08a09a05a06a04/Night-Stars-and-Mourning-Doves-by-Margo-Hoornstra.pdf