Malicious PDF — malware analysis report

Static analysis result for SHA-256 585025ef0ff4ff42…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 02:44:44 +01:00 Authoring application: mPDF 5.7
MD5: d12809c732556b011303a9aca6655364 SHA-1: bf8f8308c4544159006821ff93f968ccc5f88084 SHA-256: 585025ef0ff4ff42e854866c0710b81d2949dd0ecd5f3c0dd2e832ce1621aba5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a tactic to drive traffic to external content, potentially for SEO poisoning or to host malicious payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a01a09a06a00a04/Till-Death-Do-Us-Tart-by-H-Y-Hanna.pdf
    • http://muicuiu.dumb1.com/5a00a04a05/Till-Death-by-Jennifer-L-Armentrout.pdf
    • http://muicuiu.dumb1.com/2a09a08a04a08a04/Mostly-Murder-Till-Death-by-Lawrence-Block.pdf
    • http://muicuiu.dumb1.com/1a00a05a03a07a04a09/Till-Death-Deep-Six-Security-1-by-Becky-McGraw.pdf
    • http://muicuiu.dumb1.com/4a06a05a03a06a07/Are-We-Dead-Yet-Till-Death-Book-1-by-Hannah-Trank.pdf
    • http://muicuiu.dumb1.com/1a07a01a05a01a05/Till-Death-The-Dumont-Diaries-3-by-Alessandra-Torre.pdf
    • http://muicuiu.dumb1.com/2a05a08a03a09a01/Till-Death-Deep-Six-Security-1-by-Becky-McGraw.pdf
    • http://muicuiu.dumb1.com/4a07a00a06a03a07/Articles-on-in-Death-Novel-Series-Including-In-Death-Eve-Dallas-Naked-in-Death-Roarke-in-Death-Characters-Glory-in-Death-Immortal-in-Death-Vengeance-in-Death-in-Death-Technology-Origin-in-Death-Memory-in-Death-Novel-by-Hephaestus-Books.pdf
    • http://muicuiu.dumb1.com/1a03a05a09a07a03/-Till-Death-Do-Us-Part-Zombie-Fallout-6-by-Mark-Tufo.pdf
    • http://muicuiu.dumb1.com/8a03a01a07a02/Till-Death-Do-Us-Part-April-Lancaster-1-by-Lurlene-McDaniel.pdf
    • http://muicuiu.dumb1.com/2a02a06a01a02a04/Till-Death-Do-Us-Part-Bis-dass-der-Tod-uns-scheidet-by-Kendra-North.pdf
    • http://muicuiu.dumb1.com/8a00a03a06a09/Till-Death-Do-Us-Bark-43-Old-Cemetery-Road-3-by-Kate-Klise.pdf
    • http://muicuiu.dumb1.com/1a01a07a04a02a02/Till-Death-Do-Us-Bark-Dog-Walker-Mysteries-5-by-Judi-McCoy.pdf
    • http://muicuiu.dumb1.com/1a04a03a09a06a02/Death-of-Innocence-The-Story-of-the-Hate-Crime-That-Changed-America-by-Mamie-Till-Mobley.pdf
    • http://muicuiu.dumb1.com/5a06a08a04a08a05/The-Gender-of-Suicide-Knowledge-Production-Theory-and-Suicidology-Katrina-Jaworski-by-Katrina-Jaworski.pdf
    • http://muicuiu.dumb1.com/1a01a02a09a06a09a02/Recollections-Of-Alexander-H-Stephens-His-Diary-Kept-When-A-Prisoner-At-Fort-Warren-Boston-Harbou-by-Alexander-H-Stephens.pdf
    • http://muicuiu.dumb1.com/6a00a00a06a06a00/The-Chronicles-of-Katrina-The-Chronicles-of-Katrina-1-4-by-Karin-Tabke.pdf
    • http://muicuiu.dumb1.com/2a00a00a05a05a06/Enslaved-by-Virginia-Henley.pdf
    • http://muicuiu.dumb1.com/4a05a02a00a00a01/Enslaved-Fire-and-Ice-3-by-Kim-Faulks.pdf
    • http://muicuiu.dumb1.com/1a07a04a05a07a07/The-Spawning-Enslaved-2-by-Kaitlyn-O-39-Connor.pdf
    • http://muicuiu.dumb1.com/4a07a00a06a03a07/Articles-on-in-Death-Novel-Series-Including-In-Death-Eve-Dallas-Naked-in-Death-Roarke-in-Death-Ch