Malicious PDF — malware analysis report

Static analysis result for SHA-256 57e3c3832ec9c7a1…

MALICIOUS

PDF

20.8 KB Created: 2019-04-30 05:34:17 +01:00 Authoring application: mPDF 5.7
MD5: 5e36864746723d82f0e243ed7f4bfb1c SHA-1: 8adf2b969fa6ba6feee076a8ba598a9c3581f839 SHA-256: 57e3c3832ec9c7a189fec863fa639df067ff269ec0ce740ff901d94af2fcbaec
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself, combined with the heuristic firing of PDF_SEO_LINK_FARM, suggests the primary attack pattern is to leverage these links. The URLs themselves are currently marked as benign, but the sheer volume and the heuristic suggest a malicious intent behind their inclusion.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a06a09a09a07a00/Therapy-Games-Creative-Ways-to-Turn-Popular-Games-Into-Activities-That-Build-Self-Esteem-Teamwork-Communication-Skills-Anger-Management-Self-Discovery-and-Coping-Skills-by-Alanna-Jones.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a02a02/Mahi-Mahi-Recipes-Delicious-Mahi-Mahi-Recipes-For-Every-Occasion-by-Arthur-Devalle.pdf
    • http://muicuiu.dumb1.com/5a05a08a06a04a03/Effective-Communication-Skills-by-Dalton-Kehoe.pdf
    • http://muicuiu.dumb1.com/5a01a01a03a08a04/Good-Practice-Communication-Skills-in-English-for-the-Medical-Practitioner-Student-s-Book-by-Marie-McCullagh.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a07a05/Recipe-11-From-A-Billionaires-Table-Mahi-Mahi-Mango-Salsa-and-Red-Pepper-Coulis-by-Dylan-Grey.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a03a02/aaja-mahi-aaja-mahi-Video-Song-Aaryan-by-saruar.pdf
    • http://muicuiu.dumb1.com/5a05a08a07a01a00/Mass-Communication-Theory-Foundations-Ferment-and-Future-with-InfoTrac-Wadsworth-Series-in-Mass-Communication-and-Journalism-by-Stanley-J-Baran.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a08a09/It-s-All-About-Mahi-by-Ankit-Pathak.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a09a08/Computer-Netwoking-by-Mahi.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a03a05/Rediscovering-Our-Heart-by-Mahi.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a07a09/Nga-Mahi-The-Things-We-Need-to-Do-by-Jason-Hartley.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a00a00/A-Dream---Once-Upon-a-Quiet-Mind-by-Mahi.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a02a00/Principles-of-Metal-Casting-by-Mahi-Sahoo.pdf
    • http://muicuiu.dumb1.com/4a05a07a08a05a05/Breadfruit-Materena-Mahi-1-by-C-lestine-Hitiura-Vaite.pdf
    • http://muicuiu.dumb1.com/6a05a07a00a03a01/Te-Mahi-Kete-Maori-Basketry-For-Beginners-by-Mick-Pendergrast.pdf
    • http://muicuiu.dumb1.com/6a05a07a02a05a07/Encyclopedie-de-L-Islam-Tome-5-Khe-Mahi-Livr-79-98-98a-by-Clifford-Edmund-Bosworth.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a08a05/Pakistan-Ke-Tazah-Paniyo_n-KI-Itlaqi-Mahi-Parvari-by-Mohammad-Asif.pdf
    • http://muicuiu.dumb1.com/6a05a07a01a07a07/Warrior-s-Children-A-Healing-Book-For-The-Families-Of-Veterans-by-Trisha-Mahi.pdf
    • http://muicuiu.dumb1.com/6a05a07a02a05a09/Gaiaku-Luiza-E-a-Trajetoria-Do-Jeje-Mahi-Na-Bahia-by-Marcos-Carvalho.pdf
    • http://muicuiu.dumb1.com/6a06a04a07a05a09/Advocacy-Skills-by-Michael-Hyam.pdf