Malicious PDF — malware analysis report

Static analysis result for SHA-256 8174d644e95e54cb…

MALICIOUS

PDF

15.6 KB Created: 2019-05-07 04:20:36 +01:00 Authoring application: mPDF 5.7
MD5: 0c0bec5d5534a24e30b395c06e436eeb SHA-1: 8676d0119619629fcd2849e701883a40fa19c002 SHA-256: 8174d644e95e54cb664d1f19db5bc3a14f636da8a057d5a7f866bac9cfe2e0ca
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific URLs extracted were benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern of hosting numerous external links. The ML classifier also flagged this PDF as malicious with high confidence. The presence of these links suggests a potential for distributing malicious content or for SEO manipulation, which is a common tactic for phishing or malware distribution campaigns.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a00a09a03a02a00/From-Alice-to-Buena-Vista-The-Films-of-Wim-Wenders-by-Roger-Bromley.pdf
    • http://muicuiu.dumb1.com/9a00a09a01a08a07/Islands-of-Silence-Donata-Wenders-by-Donata-Wenders.pdf
    • http://muicuiu.dumb1.com/9a00a09a03a00a02/The-Heart-is-a-Sleeping-Beauty-The-Million-Dollar-Hotel-by-Donata-Wenders.pdf
    • http://muicuiu.dumb1.com/9a00a09a04a06a03/Wim-Wenders-Written-in-the-West-Revisited-by-Wim-Wenders.pdf
    • http://muicuiu.dumb1.com/1a05a05a01a09a03/The-Shy-Girls-Social-Club-by-Kailin-Gow.pdf
    • http://muicuiu.dumb1.com/2a05a06a02a08a06/Savior-Tattered-Social-Club-1-by-Pauline-Allan.pdf
    • http://muicuiu.dumb1.com/3a07a06a09a00a05/Bayou-s-End-Rougaroux-Social-Club-2-by-Lynn-Lorenz.pdf
    • http://muicuiu.dumb1.com/3a05a03a07a02a06/Bayou-Loup-Rougaroux-Social-Club-3-by-Lynn-Lorenz.pdf
    • http://muicuiu.dumb1.com/3a08a07a08a05a06/The-Gathering-Place-Stories-from-the-Armenian-Social-Club-in-Old-Shanghai-by-E-G-Sergoyan.pdf
    • http://muicuiu.dumb1.com/4a07a01a09a05a09/Brothers-of-Tierra-Buena-by-Al-Carty.pdf
    • http://muicuiu.dumb1.com/9a09a07a07a05a06/La-vida-es-buena-si-no-te-rindes-by-Seth.pdf
    • http://muicuiu.dumb1.com/7a08a03a03a00a01/Isla-Vista-Enclave-by-James-Andrew-Lee.pdf
    • http://muicuiu.dumb1.com/4a01a01a09a00a07/The-Good-Daughter-Vista-Security-1-by-Diana-Layne.pdf
    • http://muicuiu.dumb1.com/5a00a01a00a05a00/Gays-of-Our-Lives-Queers-of-La-Vista-1-by-Kris-Ripper.pdf
    • http://muicuiu.dumb1.com/9a00a09a01a08a05/Places-Strange-and-Quiet-by-Wim-Wenders.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a01a01a01/Dresden-Go-Vista-City-Info-Guides-by-Roland-Mischke.pdf
    • http://muicuiu.dumb1.com/9a00a09a04a06a01/The-Poetics-of-Absence-A-Study-of-Antonioni-and-Wenders-by-Yuk-Wa-Law.pdf
    • http://muicuiu.dumb1.com/9a00a09a03a01a00/A-Sense-of-Place-Texte-und-Interviews-by-Wim-Wenders.pdf
    • http://muicuiu.dumb1.com/9a09a07a01a06a06/London-Go-Vista-City-Info-Guides-by-Hans-G-nter-Semsek.pdf
    • http://muicuiu.dumb1.com/9a00a09a01a08a06/My-Time-with-Antonioni-The-Diary-of-an-Extraordinary-Experience-by-Wim-Wenders.pdf