Malicious PDF — malware analysis report

Static analysis result for SHA-256 7addf0570ab7c5e4…

MALICIOUS

PDF

18.4 KB Created: 2019-04-29 23:27:52 +01:00 Authoring application: mPDF 5.7
MD5: 9126ef6d9c9e4ae37d72d3c2feaf6611 SHA-1: d118c05c9756914aa9b254584bcd72e00a230c39 SHA-256: 7addf0570ab7c5e45bba3bf4e6beea3c65cceab9a874909172b02559415e357d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself is indicative of a link farm designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a02a08a00a09a02/The-Nostradamus-Secret-Bob-Danforth-3-by-Joseph-Badal.pdf
    • http://muicuiu.dumb1.com/7a04a07a06a00a05/Nostradamus-and-the-Nineties-Prophecies-of-Nostradamus-Pertaining-to-the-1990s-by-Nostradamus.pdf
    • http://muicuiu.dumb1.com/7a04a07a07a00a06/The-Secret-Prophecies-of-Nostradamus-by-Cynthia-Sternau.pdf
    • http://muicuiu.dumb1.com/6a08a06a07a09a03/The-First-Face-of-Janus-Secret-Society-of-Nostradamus-by-Phil-Valentine.pdf
    • http://muicuiu.dumb1.com/7a04a07a07a00a00/The-Fortune-of-France-from-the-Prophetical-Predictions-of-Mr-Truswell-the-Recorder-of-Lincoln-and-Michael-Nostradamus-by-Nostradamus.pdf
    • http://muicuiu.dumb1.com/6a03a09a06a09/The-Writings-Of-Nostradamus-The-Complete-Prophecies-For-The-Future-Past-And-Present-Including-The-Almanacs-by-Nostradamus.pdf
    • http://muicuiu.dumb1.com/6a03a07a04a08a07/The-Secret-Sharer-Le-Compagnon-Secret-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/7a04a07a05a05a01/Nostradamus-His-Works-and-Prophecies-by-Nostradamus.pdf
    • http://muicuiu.dumb1.com/7a04a07a04a08a00/Prophecies-of-Nostradamus-by-Nostradamus.pdf
    • http://muicuiu.dumb1.com/4a09a04a02a06a06/Three-Modern-Indian-Plays-by-Badal-Sircar.pdf
    • http://muicuiu.dumb1.com/1a02a08a06a09a07/The-Secret-Signature-of-Things-by-Eve-Joseph.pdf
    • http://muicuiu.dumb1.com/5a08a00a05a04a08/Secret-Agent-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/4a02a06a04a06a01/The-Secret-Sharer-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/6a06a06a02a09a01/The-Vatican-s-Last-Secret-by-Francis-Joseph-Smith.pdf
    • http://muicuiu.dumb1.com/2a06a03a09a03a07/The-Secret-Sharer-and-other-stories-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/3a02a05a05a04a09/The-Secret-Sharer-and-Other-Stories-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/9a00a02a05a09a04/Though-Murder-Has-No-Tongue-The-Lost-Victim-of-Cleveland-s-Mad-Butcher-by-James-Jessen-Badal.pdf
    • http://muicuiu.dumb1.com/2a05a07a08a00a02/The-Secret-World-Of-The-Irish-Male-by-Joseph-O-39-Connor.pdf
    • http://muicuiu.dumb1.com/2a02a07a06a07a04/The-Secret-Agent-A-Simple-Tale-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/4a01a00a00a02a01/The-Secret-Agent-A-Simple-Tale-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/6a03a09a06a09/The-Writings-Of-Nostrad