Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e043cde03622f54…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 04:30:54 +01:00 Authoring application: mPDF 5.7
MD5: 7309a6b8bd007ef4db78b5c4ac5e48e3 SHA-1: 77d09d45f6fad12ed38e9f4fbbd850dc87805475 SHA-256: 7e043cde03622f54a57016528cd0aced749b3f660b348ee7342e14a4e749245c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a large number of embedded URLs, forming a link farm. This is a common technique for SEO poisoning or directing users to malicious content. While no scripts were extracted, the ML classifier and the PDF_SEO_LINK_FARM heuristic strongly indicate malicious intent. The URLs themselves appear to be benign, but their sheer volume and the context of the heuristic firing suggest a malicious purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a09a06a05a06a04/George-Washington-Frontier-Colonel-by-Sterling-North.pdf
    • http://muicuiu.dumb1.com/1a04a07a04a08/Abe-Lincoln-Log-Cabin-to-White-House-by-Sterling-North.pdf
    • http://muicuiu.dumb1.com/5a01a03a06a09a02/The-Spanish-Frontier-in-North-America-by-David-J-Weber.pdf
    • http://muicuiu.dumb1.com/5a09a06a05a00a02/Bringing-Down-the-Colonel-A-Sex-Scandal-of-the-Gilded-Age-and-the-quot-powerless-quot-Woman-Who-Took-on-Washington-by-Patricia-Miller.pdf
    • http://muicuiu.dumb1.com/5a01a03a06a08a06/John-Sutter-A-Life-on-the-North-American-Frontier-by-Albert-L-Hurtado.pdf
    • http://muicuiu.dumb1.com/2a00a09a04a07a00/The-Eternal-Frontier-An-Ecological-History-of-North-America-and-Its-Peoples-by-Tim-Flannery.pdf
    • http://muicuiu.dumb1.com/4a09a08a02a03a07/The-Colonel-The-Extraordinary-Story-of-Colonel-Tom-Parker-and-Elvis-Presley-by-Alanna-Nash.pdf
    • http://muicuiu.dumb1.com/1a09a04a07a04a04/Writings-by-George-Washington.pdf
    • http://muicuiu.dumb1.com/1a00a01a04a06a03a03/George-Washington-s-Spy-by-Elvira-Woodruff.pdf
    • http://muicuiu.dumb1.com/2a08a09a01a02a04/George-Washington-by-Ingri-d-39-Aulaire.pdf
    • http://muicuiu.dumb1.com/7a08a07a04a03a03/The-Cavalier-by-George-Washington-Cable.pdf
    • http://muicuiu.dumb1.com/2a05a00a06a04a06/George-Washington-Werewolf-by-Kevin-Postupack.pdf
    • http://muicuiu.dumb1.com/7a07a07a05a09a00/The-Flower-of-the-Chapdelaines-by-George-Washington-Cable.pdf
    • http://muicuiu.dumb1.com/3a08a04a03a05a00/George-Washington-by-Willard-Sterne-Randall.pdf
    • http://muicuiu.dumb1.com/1a00a03a02a04a09/His-Excellency-George-Washington-by-Joseph-J-Ellis.pdf
    • http://muicuiu.dumb1.com/7a05a04a06a06a03/George-Washington-s-Sacred-Fire-by-Peter-A-Lillback.pdf
    • http://muicuiu.dumb1.com/3a09a06a06a03/George-Washington-Carver-The-Man-Who-Overcame-by-Lawrence-Elliott.pdf
    • http://muicuiu.dumb1.com/8a06a03a02a05a01/A-Picture-Book-of-George-Washington-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/2a09a00a08a06a09/George-Washington-Gomez-A-Mexicotexan-Novel-by-Am-rico-Paredes.pdf
    • http://muicuiu.dumb1.com/8a08a05a05a07a01/George-Washington-s-War-The-Saga-of-the-American-Revolution-by-Robert-Leckie.pdf