Malicious PDF — malware analysis report

Static analysis result for SHA-256 852aee785e5a779b…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 01:30:09 +01:00 Authoring application: mPDF 5.7
MD5: 1b7751268c241603ca367d3f8a194907 SHA-1: 993950d7cabee677b8ffbd07870f5663e848de21 SHA-256: 852aee785e5a779baf8ed63fbd63b0790a5c4dcb5db7cba55873b22816f3307e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links point to a domain that hosts numerous book titles, suggesting a potential lure to a content farm or a site designed to host malicious payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a00a08a04a04/Sky-Song-Sky-Song-trilogy-1-by-Sharon-Sant.pdf
    • http://muicuiu.dumb1.com/1a07a06a06a01a00/Wolf-Song-Wolf-Song-Trilogy-1-by-Frank-W-Smith.pdf
    • http://muicuiu.dumb1.com/4a03a07a06a02a04/Two-Songs-Song-of-Prisoner-amp-Song-of-Malaya-by-Okot-p-39-Bitek.pdf
    • http://muicuiu.dumb1.com/2a07a02a07a05a03/Remember-Our-Song-A-Billionaire-Romance-Our-Song-3-by-Emma-South.pdf
    • http://muicuiu.dumb1.com/2a00a00a09a02a01/Warrior-s-Song-Medieval-Song-1-by-Catherine-Coulter.pdf
    • http://muicuiu.dumb1.com/4a07a05a01a04a09/Fire-Song-Siren-Song-3-by-Roberta-Gellis.pdf
    • http://muicuiu.dumb1.com/4a00a00a04a07a09/Secret-Song-Medieval-Song-4-by-Catherine-Coulter.pdf
    • http://muicuiu.dumb1.com/2a07a03a00a05a02/A-Song-of-Ice-and-Fire-5-Book-Boxed-Set-A-Game-of-Thrones-A-Clash-of-Kings-A-Storm-of-Swords-A-Feast-for-Crows-A-Dance-with-Dragons-Song-of-Ice-amp-Fire-1-5-by-George-R-R-Martin.pdf
    • http://muicuiu.dumb1.com/1a02a04a02a07a00/Fire-amp-Ice-Faerie-Song-Trilogy-1-by-Michele-Barrow-Belisle.pdf
    • http://muicuiu.dumb1.com/5a03a00a02a01a06/Swan-Song-Book-Three-in-The-Icarus-Trilogy-by-Kevin-Kauffmann.pdf
    • http://muicuiu.dumb1.com/7a07a01a04a01a05/By-the-Shores-of-the-Middle-Sea-Silk-and-Song-Trilogy-2-by-Dana-Stabenow.pdf
    • http://muicuiu.dumb1.com/3a07a08a07a01a09/Love-Song-Liebeslied-Captive-Heart-Trilogy-1-by-Stephanie-Baumgartner.pdf
    • http://muicuiu.dumb1.com/1a08a01a09a05a08/The-Memory-Game-by-Sharon-Sant.pdf
    • http://muicuiu.dumb1.com/4a06a08a09a01a06/Tell-Me-Why-The-Beatles-Album-By-Album-Song-By-Song-The-Sixties-And-After-by-Tim-Riley.pdf
    • http://muicuiu.dumb1.com/1a01a01a06a07a05a09/Messiaen-s-Explorations-of-Love-and-Death-Musico-Poetic-Signification-in-the-Tristan-Trilogy-and-Three-Related-Song-Cycles-by-Siglind-Bruhn.pdf
    • http://muicuiu.dumb1.com/2a05a00a07a03a03/Witch-Song-Witch-Song-1-by-Amber-Argyle.pdf
    • http://muicuiu.dumb1.com/4a01a05a09a06a06/Rebel-Song-Rebel-Song-1-by-Amanda-J-Clay.pdf
    • http://muicuiu.dumb1.com/1a01a05a02a01a01a09/The-Lyrics-To-His-Song-2-The-Lyrics-To-His-Song-2-by-Krystal-Armstead.pdf
    • http://muicuiu.dumb1.com/3a08a02a01a09a06/A-Song-for-No-Man-s-Land-A-Song-for-No-Man-s-Land-1-by-Andy-Remic.pdf
    • http://muicuiu.dumb1.com/3a04a01a01a00/A-Song-of-Ice-and-Fire-A-Song-of-Ice-and-Fire-1-4-by-George-R-R-Martin.pdf
    • http://muicuiu.dumb1.com/2a07a03a00a05a02/A-Song-of-Ice-and-Fire-5-Book-Boxed-Set-A-Game-of-Thrones-A-Clash-of-Kings-A-Storm-of-Swords-A-Feast-for-Crows-A-Dance-with-Dragons-Song-of-Ice-amp-Fir