Malicious PDF — malware analysis report

Static analysis result for SHA-256 86dc4e9d59e5c664…

MALICIOUS

PDF

18.8 KB Created: 2019-05-02 01:25:58 +01:00 Authoring application: mPDF 5.7
MD5: 9471b219ac4c111291475b433ba18869 SHA-1: 4fd7906df3a50cc96745e57062a3c85455a628ed SHA-256: 86dc4e9d59e5c664c855805073eba0fd1608b3f2cd45da3407f13084f1fde75c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu
    • http://muicuiu.dumb1.com/9a07a01a08a00/Spark-City-Book-One-of-the-Spark-City-Cycle-by-Robert-J-Power.pdf
    • http://muicuiu.dumb1.com/3a00a08a06a02a05/The-Waffle-Chronicles-82-Flufftastic-Waffles-Recipes-Recipe-Spark-Food-Series-Book-1-by-Recipe-Spark.pdf
    • http://muicuiu.dumb1.com/4a04a00a08a00a03/The-Spark-of-a-Kiss-Park-City-Firefighter-Romance-Station-2-by-Sarah-Gay.pdf
    • http://muicuiu.dumb1.com/1a00a05a00a04a03a05/Big-Data-Analytics-with-Spark-A-Practitioner-s-Guide-to-Using-Spark-for-Large-Scale-Data-Analysis-by-Mohammed-Guller.pdf
    • http://muicuiu.dumb1.com/9a08a07a07a07a01/Spark-Spark-1-by-Brooke-Cumberland.pdf
    • http://muicuiu.dumb1.com/1a01a03a00a01a00/Spark-Spark-1-by-Rachael-Craw.pdf
    • http://muicuiu.dumb1.com/5a08a03a09a07a08/The-Collected-Stories-of-Muriel-Spark-by-Muriel-Spark.pdf
    • http://muicuiu.dumb1.com/5a08a04a00a09a07/Complete-Poems-Muriel-Spark-by-Muriel-Spark.pdf
    • http://muicuiu.dumb1.com/3a05a08a05a00a06/City-of-Boneheads-A-Parody-of-City-of-Bones-The-Mortal-Instruments-Book-1-by-Steve-Lookner.pdf
    • http://muicuiu.dumb1.com/4a00a09a05a04a02/ONE-CITY-DAY-LOVE-CITY-STRINGS-Book-1-by-SIDDHARTH-NAIDU.pdf
    • http://muicuiu.dumb1.com/2a05a06a06a02a04/Strumpet-City-One-City-One-Book-Edition-by-James-Plunkett.pdf
    • http://muicuiu.dumb1.com/5a05a04a01a02a01/Fictional-City-States-Laputa-Baldur-s-Gate-Gaia-Mega-City-One-Ankh-Morpork-New-Crobuzon-Themyscira-Free-City-of-Greyhawk-Sanctaphrax-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a07a03a01/Tales-from-Null-City-From-the-World-of-Null-City-Book-3-by-Barb-Taub.pdf
    • http://muicuiu.dumb1.com/3a05a03a07a07a08/Succubus-and-the-City-The-Rowan-Harbor-Cycle-4-5-by-Sam-Burns.pdf
    • http://muicuiu.dumb1.com/4a01a01a08a01a07/The-Comforters-by-Muriel-Spark.pdf
    • http://muicuiu.dumb1.com/3a00a09a02a07/The-Spark-by-Kristine-Barnett.pdf
    • http://muicuiu.dumb1.com/5a08a04a00a04a07/The-Bachelors-by-Muriel-Spark.pdf
    • http://muicuiu.dumb1.com/1a02a02a08a03a01/The-Spark-by-John-Kenny.pdf
    • http://muicuiu.dumb1.com/5a09a06a00a08/A-Far-Cry-from-Kensington-by-Muriel-Spark.pdf
    • http://muicuiu.dumb1.com/1a08a08a02a01a08/When-Sparks-Fly-Spark-1-by-Autumn-Dawn.pdf