Malicious PDF — malware analysis report

Static analysis result for SHA-256 5542b50288c8c9b2…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 05:39:17 +01:00 Authoring application: mPDF 5.7
MD5: bb8cd4df13cc8a7e9a3cef20b693220f SHA-1: 5c6c49f14d7ce2b5bb59610e3cf2d70c2683a6dd SHA-256: 5542b50288c8c9b2bf35dc2076ce53409bf41f7b6ef4f9e3650aa2f88213651f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or SEO poisoning attack. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. While no scripts were extracted, the sheer volume of links points to a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a04a09a06a01a02/The-Complete-Fiction-of-Nella-Larsen-Passing-Quicksand-and-the-Stories-by-Nella-Larsen.pdf
    • http://muicuiu.dumb1.com/1a00a02a08a02a00/Quicksand-and-Passing-by-Nella-Larsen.pdf
    • http://muicuiu.dumb1.com/3a07a00a08a07a01/Passing-by-Nella-Larsen.pdf
    • http://muicuiu.dumb1.com/8a00a04a04a00/Nella-Last-s-War-The-Second-World-War-Diaries-of-Housewife-49-by-Nella-Last.pdf
    • http://muicuiu.dumb1.com/1a06a06a06a00a02/The-Primer-s-Tale-by-Nella-Grace.pdf
    • http://muicuiu.dumb1.com/1a01a05a04a06a02a06/L-interpretazione-nella-psicoanalisi-contemporanea-l-efficacia-by-Sandro-Panizza.pdf
    • http://muicuiu.dumb1.com/5a08a00a08a00a07/Ruba-come-un-artista-Per-essere-pi-creativo-nel-lavoro-e-nella-vita-by-Austin-Kleon.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a03a06a06/Il-Settecento-e-l-Influenza-Francese-I-Costumi-degli-Italiani-nella-Storia-by-Schriftsteller-Verschiedene.pdf
    • http://muicuiu.dumb1.com/1a01a05a02a04a04a05/Fai-spazio-nella-tua-vita-Come-trovare-la-felicit-con-l-arte-dell-essenziale-by-Fumio-Sasaki.pdf
    • http://muicuiu.dumb1.com/6a04a03a07a02a02/Totem-e-tab-Alcune-concordanze-nella-vita-psichica-dei-selvaggi-e-dei-nevrotici-by-Sigmund-Freud.pdf
    • http://muicuiu.dumb1.com/1a01a07a05a07a05a00/Festa-Datasi-Dal-Sig-Conte-A-G-Batthyany-La-Sera-del-30-Gennajo-1828-Nella-Sua-Casa-in-Milano-by-Angelo-Bonfanti.pdf
    • http://muicuiu.dumb1.com/3a03a05a09a01a09/The-Tutor-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/1a02a06a05a01a09/Run-The-Hunted-1-by-Patti-Larsen.pdf
    • http://muicuiu.dumb1.com/8a09a09a06a07/Popgun-Vol-1-by-Erik-Larsen.pdf
    • http://muicuiu.dumb1.com/3a01a08a05a07a09/Resistance-Bloodlines-3-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/9a09a04a03a08a06/Ich-will-harten-Sex-by-Niklas-Larsen.pdf
    • http://muicuiu.dumb1.com/1a06a06a03a04a08/Committed-30-Days-2-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/4a03a04a03a02a01/Saving-Caroline-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/4a03a04a03a03a00/Dating-Delaney-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/1a04a06a05a08a04/Dating-Delaney-by-K-Larsen.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a03a06a06/Il-Settecento-e-l-Influenza-Fr