Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a943448d71232a6…

MALICIOUS

PDF

18.7 KB Created: 2019-05-07 09:42:08 +01:00 Authoring application: mPDF 5.7
MD5: 9c77a2333459a58cae858a2adedd2327 SHA-1: 2be8659d1d6e460109df92efc56ad028bf1c1212 SHA-256: 7a943448d71232a63e7d55f9443dfdc6b7fe3e1f03b28d86967ee66d2e43fa2d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links were classified as benign, the sheer volume and the critical severity of the heuristic suggest a malicious intent to direct users to external resources. The ML classifier also strongly indicated maliciousness. The primary attack pattern involves a link farm designed to overwhelm or deceive the user into clicking through to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a09a05a04a03a01/The-Ring-of-Fire-Young-Samurai-6-by-Chris-Bradford.pdf
    • http://muicuiu.dumb1.com/6a04a05a08a07/The-Ring-of-Water-Young-Samurai-5-by-Chris-Bradford.pdf
    • http://muicuiu.dumb1.com/6a00a00a08a08/The-Way-of-the-Dragon-Young-Samurai-3-by-Chris-Bradford.pdf
    • http://muicuiu.dumb1.com/8a06a03a01a02/Novels-by-Chris-D-lacey-The-Fire-Eternal-Fire-Star-the-Fire-Within-Icefire-the-Last-Dragon-Chronicles-Fire-World-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/3a01a07a00a02a08/Young-Men-and-Fire-A-True-Story-of-the-Mann-Gulch-Fire-by-Norman-Maclean.pdf
    • http://muicuiu.dumb1.com/4a06a05a01a01a01/Dragon-Dreams-and-Fairy-Wings-Fire-amp-Flutter-1-by-Bailey-Bradford.pdf
    • http://muicuiu.dumb1.com/9a05a08a09a05a05/Through-the-Fire-Based-on-a-True-Story-About-a-Young-Girl-That-Was-Maliciously-Burned-in-a-House-Fire-by-Theresa-A-Vandermeer.pdf
    • http://muicuiu.dumb1.com/4a04a07a01a01a03/Smokeless-Fire-Fire-Spirits-1-by-Samantha-Young.pdf
    • http://muicuiu.dumb1.com/4a03a02a07a08/Smokeless-Fire-Fire-Spirits-1-by-Samantha-Young.pdf
    • http://muicuiu.dumb1.com/1a01a00a04a03a05/Ring-of-Fire-Century-1-by-Pierdomenico-Baccalario.pdf
    • http://muicuiu.dumb1.com/5a08a02a06a09a00/Doc-Savage-The-Ring-of-Fire-by-David-Avallone.pdf
    • http://muicuiu.dumb1.com/5a08a02a07a06a05/Doc-Savage-Ring-Of-Fire-4-by-David-Avallone.pdf
    • http://muicuiu.dumb1.com/1a03a05a08a03a07/Eternal-Fire-The-Ruby-Ring-3-by-Chrissy-Peebles.pdf
    • http://muicuiu.dumb1.com/6a03a00a00a00a06/Ring-of-Hell-The-Story-of-Chris-Benoit-and-the-Fall-of-the-Pro-Wrestling-Industry-by-Matthew-Randazzo-V.pdf
    • http://muicuiu.dumb1.com/1a09a05a03a06a04/The-New-Order-The-Young-World-2-by-Chris-Weitz.pdf
    • http://muicuiu.dumb1.com/3a05a07a02a03a05/Only-the-Ring-Finger-Knows-The-Ring-Will-Confess-His-Love-Only-the-Ring-Finger-Knows-4-by-Satoru-Kannagi.pdf
    • http://muicuiu.dumb1.com/3a09a05a07a09a00/Land-Of-Fire-by-Chris-Ryan.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05/Young-Men-and-Fire-by-Norman-Maclean.pdf
    • http://muicuiu.dumb1.com/4a00a09a01a06a03/Trial-By-Fire-Going-Down-in-Flames-3-by-Chris-Cannon.pdf
    • http://muicuiu.dumb1.com/1a03a01a00a09a08/Trial-By-Fire-Going-Down-in-Flames-3-by-Chris-Cannon.pdf
    • http://muicuiu.dumb1.com/9a05a08a09a05a05/Through-the-Fire-Based-on-a-True-Story-About-a-Young-Girl-That-Was-Maliciously-Burned-in-a-House-Fire-by-Theresa-A-Vande