Malicious PDF — malware analysis report

Static analysis result for SHA-256 8243f1cca689929d…

MALICIOUS

PDF

25.0 KB Created: 2019-05-09 00:19:26 +01:00 Authoring application: mPDF 5.7
MD5: eebd5fe7fc665a492f1846a8dea30126 SHA-1: 4fd3d23b82fdfba898fb2e02ce69afb60b0abac4 SHA-256: 8243f1cca689929dd944bf3abc339142e5dc0801623a37cc21fccf40bb016a4e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a06a03a00a06a07/DinoMechs-Battle-Force-Jurassic-by-Isaac-Stone.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a06a00/Jurassic-Park-Michael-Crichton-List-of-Jurassic-Park-Characters-the-Lost-World-Jurassic-Park-Jurassic-Park-III-Biological-Issue-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a08a08a00/Jurassic-Strike-Force-5-by-Neo-Edmund.pdf
    • http://muicuiu.dumb1.com/2a05a03a06a03a07/Air-Battle-Force-Patrick-McLanahan-11-by-Dale-Brown.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a08a02a08/Jurassic-Sea-Jurassic-Adventures-2-by-Viktor-Zarkov.pdf
    • http://muicuiu.dumb1.com/3a03a01a00a09a04/Malik-s-Redemption-Delta-Force-Team-Panther-3-by-Annabella-Stone.pdf
    • http://muicuiu.dumb1.com/3a03a01a04a06a00/Jonah-s-Compass-Delta-Force-Team-Panther-1-by-Annabella-Stone.pdf
    • http://muicuiu.dumb1.com/5a00a02a03a01/Jurassic-Park-The-Lost-World-Jurassic-Park-1-2-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/1a03a07a06a01a00/Jurassic-World-Jurassic-Park-The-Lost-World-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a08a08a05/Jurassic-Earth-2-Prologue-The-Last-Woman-on-Earth-The-Jurassic-Earth-Saga-by-Logan-T-Stark.pdf
    • http://muicuiu.dumb1.com/1a00a08a07a00a06a01/Focus-On-30-Most-Popular-Battles-of-World-War-II-Involving-the-United-States-Battle-of-Iwo-Jima-Omaha-Beach-Battle-of-Anzio-Battle-of-H-rtgen-Forest-in-Italy-Operation-Nordwind-etc-by-Wikipedia-contributors.pdf
    • http://muicuiu.dumb1.com/1a02a04a03a00a08/Isaac-the-Alchemist-Secrets-of-Isaac-Newton-Reveal-d-by-Mary-Losure.pdf
    • http://muicuiu.dumb1.com/3a01a03a00a06a08/Discovering-Isaac-The-Beloved-Potter-of-Niederbipp-Remembering-Isaac-2-by-Ben-Behunin.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a09a08a02/Battle-Angel-Alita---Battle-Angel-Alita-Last-Order-Battle-Angel-Alita-Last-Order-Chapters-Battle-Angel-Alita-Last-Order-Characters-Battle-Angel-Alita-Last-Order-Images-Battle-Angel-Alita-Last-Order-Locations-Battle-Angel-Alita-Last-Order-Reader-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/4a07a05a03a09a00/Force-of-the-Dark-Wolf-Force-of-Nature-2-by-Kathi-S-Barton.pdf
    • http://muicuiu.dumb1.com/3a02a07a06a00a05/Force-Force-of-Nature-6-by-Kathi-S-Barton.pdf
    • http://muicuiu.dumb1.com/3a02a07a03a00a08/Space-Shuttles-Isaac-Asimov-s-Wonderful-Worlds-of-Science-Fiction-7-by-Isaac-Asimov.pdf
    • http://muicuiu.dumb1.com/4a09a03a09a00a07/Holiday-in-Stone-Creek-A-Stone-Creek-Christmas-At-Home-in-Stone-Creek-Stone-Creek-4-amp-6-by-Linda-Lael-Miller.pdf
    • http://muicuiu.dumb1.com/1a06a08a08a09a02/Remembering-Isaac-The-Wise-and-Joyful-Potter-of-Niederbipp-Remembering-Isaac-1-by-Ben-Behunin.pdf
    • http://muicuiu.dumb1.com/1a01a06a03a03a07a09/Isaac-Asimov-Presents-the-Great-SF-Stories-8-1946-by-Isaac-Asimov.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a08a08a05/Jurassic-Earth-2-Prologue-The