Malicious PDF — malware analysis report

Static analysis result for SHA-256 81262a21113d07fd…

MALICIOUS

PDF

14.3 KB Created: 2019-05-07 03:36:52 +01:00 Authoring application: mPDF 5.7
MD5: 62d71803a5de9a6c41c9b77ced76f9c0 SHA-1: b9b39f117ba1c9d473dfc60c3a6c72d2d8bde1f1 SHA-256: 81262a21113d07fddeb6eea42e959bc96f736871293f7cc741a64191e9cdc738
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. While most extracted URLs are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to redirect users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a05a08a01a01/The-Glass-Swallow-Dragonfly-amp-The-Glass-Swallow-2-by-Julia-Golding.pdf
    • http://muicuiu.dumb1.com/1a02a09a08a04a09/The-Glass-Swallow-Dragonfly-amp-The-Glass-Swallow-2-by-Julia-Golding.pdf
    • http://muicuiu.dumb1.com/3a00a06a06a08/Three-Junes-by-Julia-Glass.pdf
    • http://muicuiu.dumb1.com/2a02a02a09a01a01/Three-Junes-by-Julia-Glass.pdf
    • http://muicuiu.dumb1.com/5a09a00a00/A-House-Among-the-Trees-by-Julia-Glass.pdf
    • http://muicuiu.dumb1.com/6a07a05a09a04/Girl-Under-Glass-Glass-and-Iron-1-by-Monica-Enderle-Pierce.pdf
    • http://muicuiu.dumb1.com/2a05a01a07a08a08/And-the-Dark-Sacred-Night-by-Julia-Glass.pdf
    • http://muicuiu.dumb1.com/4a04a03a08a04a04/Shards-of-Glass-The-Glass-Trilogy-1-by-Arianne-Richmonde.pdf
    • http://muicuiu.dumb1.com/3a07a02a01a04a09/Storm-Glass-Glass-1-by-Maria-V-Snyder.pdf
    • http://muicuiu.dumb1.com/1a08a03a06a07a05/Swallow-the-Moon-by-K-A-Jordan.pdf
    • http://muicuiu.dumb1.com/2a03a00a00a04a09/Swallow-Me-Whole-by-Gemma-James.pdf
    • http://muicuiu.dumb1.com/2a03a08a03a04/Swallow-Me-Whole-by-Nate-Powell.pdf
    • http://muicuiu.dumb1.com/1a07a08a02a03/Swallow-by-Tonya-Plank.pdf
    • http://muicuiu.dumb1.com/5a00a02a05a06/The-Butterfly-Effect-by-James-Swallow.pdf
    • http://muicuiu.dumb1.com/8a04a00a03a04a05/24-Deadline-24-Live-Another-Day-1-by-James-Swallow.pdf
    • http://muicuiu.dumb1.com/3a06a01a09a00a07/It-Only-Looks-Easy-by-Pamela-Curtis-Swallow.pdf
    • http://muicuiu.dumb1.com/8a00a05a06a02a02/Game-of-the-Swallow-by-Zeina-Abirached.pdf
    • http://muicuiu.dumb1.com/4a02a02a07a01a03/Swallow-the-Air-by-Tara-June-Winch.pdf
    • http://muicuiu.dumb1.com/2a06a05a05a06a00/Snow-Kissed-by-Lisa-Swallow.pdf
    • http://muicuiu.dumb1.com/5a01a02a04a04a06/Swallow-Summer-by-Larissa-Boehning.pdf