Malicious PDF — malware analysis report

Static analysis result for SHA-256 55674ad7964128c3…

MALICIOUS

PDF

17.7 KB Created: 2019-04-30 09:44:53 +01:00 Authoring application: mPDF 5.7
MD5: 0c35e18119f2e1d971aedd87040028e2 SHA-1: 81672bcabf53ea5b6b7679f3c38fe46d4a6add34 SHA-256: 55674ad7964128c3b566f239d730d01f6cc97faea87f455aea5bebb7aa987f3d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While most URLs appear benign, the sheer volume and the heuristic 'PDF_SEO_LINK_FARM' indicate a malicious intent to redirect users. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb
    • http://muicuiu.dumb1.com/8a05a02a04a08a07/Southern-Spice-Southern-Desires-1-by-Jeannette-Winters.pdf
    • http://muicuiu.dumb1.com/3a07a04a07a01a06/Southern-Zombies-Three-Book-Box-Set-A-Story-of-Survival-Southern-Hospitality-and-Southern-Blood-by-Tracie-Ann-Riley-Lester.pdf
    • http://muicuiu.dumb1.com/8a05a02a04a06a05/Southern-Rocker-Boy-Southern-Rockers-1-by-Ginger-Voight.pdf
    • http://muicuiu.dumb1.com/3a00a02a03a08a07/Southern-Desire-Southern-Heart-2-by-Kaylee-Ryan.pdf
    • http://muicuiu.dumb1.com/4a08a05a08a07a07/Southern-Living-Fix-It-and-Freeze-It-Heat-It-and-Eat-It-A-quick-cook-guide-to-over-200-make-ahead-dishes-by-Southern-Living-Inc-.pdf
    • http://muicuiu.dumb1.com/6a03a03a06a03a07/Sweet-Tea-and-Southern-Grace-The-Southern-Grace-Series-1-by-Glenda-C-Manus.pdf
    • http://muicuiu.dumb1.com/6a03a04a04a05a05/Southern-Living-1984-Annual-Recipes-by-Southern-Living-Inc-.pdf
    • http://muicuiu.dumb1.com/1a08a05a09a08a00/Keeping-the-Dream-Alive-The-Cases-and-Causes-of-the-Southern-Poverty-Law-Center-by-Southern-Poverty-Law-Center.pdf
    • http://muicuiu.dumb1.com/3a04a08a03a07a09/Candy-by-Terry-Southern.pdf
    • http://muicuiu.dumb1.com/7a00a08a09a00a04/The-Souterrains-of-Southern-Pictland-by-F-T-Wainwright.pdf
    • http://muicuiu.dumb1.com/3a00a05a08a01a04/Southern-Cross-Vol-1-by-Becky-Cloonan.pdf
    • http://muicuiu.dumb1.com/7a03a04a03a08a03/Southern-Peloponnese-by-Sunflower-Guides.pdf
    • http://muicuiu.dumb1.com/2a00a06a05a07/Southern-Seduction-by-Alexandria-Scott.pdf
    • http://muicuiu.dumb1.com/3a09a09a06a07a05/Southern-Comfort-by-Fern-Michaels.pdf
    • http://muicuiu.dumb1.com/7a02a03a04a01a08/Flash-and-Filigree-by-Terry-Southern.pdf
    • http://muicuiu.dumb1.com/2a08a04a07a06a07/Southern-Cross-by-Terry-Coleman.pdf
    • http://muicuiu.dumb1.com/2a09a03a08a03a03/Southern-Discomfort-by-Rita-Mae-Brown.pdf
    • http://muicuiu.dumb1.com/1a04a01a04a07a00/Southern-Lights-by-Danielle-Steel.pdf
    • http://muicuiu.dumb1.com/4a03a06a01a07a00/I-Bipolar-A-Southern-Man-s-Memoir-by-D-S-Black.pdf
    • http://muicuiu.dumb1.com/7a02a08a00a02a04/3X3-Masterworks-of-southern-Go-by-Doris-Betts.pdf