Malicious PDF — malware analysis report

Static analysis result for SHA-256 55e28228ab80aade…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 05:11:57 +01:00 Authoring application: mPDF 5.7
MD5: d0fbbdb086f2c08e4e003941a869c53c SHA-1: 5c4f4dac4efef856c76cd2b70d032e0473db405a SHA-256: 55e28228ab80aadef7e6cef8f8c45e22efced5e391f61bb216792dc9d0fb0a68
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. While many of these URLs are marked as confirmed benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly for SEO manipulation or to distribute secondary payloads. The document body itself is heavily obfuscated, preventing a clear understanding of its direct user-facing purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9923

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a09a07a08a04a06/The-Book-Thief-by-Markus-Zusak----Review-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/8a01a01a00a05a07/And-the-Mountains-Echoed-by-Khaled-Hosseini---Expert-Book-Review-amp-Analysis-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/8a09a09a06a00a06/The-Husband-s-Secret-by-Liane-Moriarty----Expert-Book-Review-amp-Analysis-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a06a06a07/The-Rose-Garden-by-Susanna-Kearsley----Expert-Book-Review-amp-Analysis-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/7a04a06a04a09/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/2a04a00a08a07a02/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/7a03a03a00a09a04/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/4a00a08a02a06/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/5a02a08a02a09/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/2a09a02a01a01a09/The-Book-Thief-by-Markus-Zusak.pdf
    • http://muicuiu.dumb1.com/8a07a01a08a06a07/The-Goldfinch-by-Donna-Tartt----Review-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/7a00a07a07a09a09/A-Guide-to-The-Book-Thief-by-Markus-Zusak-by-Liss-Ross.pdf
    • http://muicuiu.dumb1.com/7a00a07a08a06a01/Study-Guide-on-The-Book-Thief-by-Markus-Zusak-Volume-51-by-Ray-Moore.pdf
    • http://muicuiu.dumb1.com/7a00a07a07a09a06/The-Book-Thief-A-Reader-s-Guide-to-the-Markus-Zusak-Novel-by-Robert-Crayola.pdf
    • http://muicuiu.dumb1.com/7a00a07a07a09a07/Bookclub-in-a-Box-Discusses-The-Book-Thief-the-novel-by-Markus-Zusak-by-Marilyn-Herbert.pdf
    • http://muicuiu.dumb1.com/1a00a00a05a02a06a06/Killer-An-Alex-Delaware-Novel-by-Jonathan-Kellerman----Review-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/5a08a02a03a01a02/The-All-Girl-Filling-Station-s-Last-Reunion-by-Fannie-Flagg----Review-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/7a00a07a08a05a08/An-Unauthorized-Guide-to-Markus-Zusak-A-Short-Biography-of-the-Author-of-The-Book-Thief-Article-by-Malcolm-Stone.pdf
    • http://muicuiu.dumb1.com/1a00a03a01a01a01a01/Divergent-Divergent-Series-By-Veronica-Roth----Review-by-Expert-Book-Reviews.pdf
    • http://muicuiu.dumb1.com/7a00a07a07a09a08/The-Book-Thief-A-Novel-by-Markus-Zusak-Trivia-On-Books-by-Trivion-Books.pdf
    • http://muicuiu.dumb1.com/7a04a06a04a09/The-Book-Thief