Malicious PDF — malware analysis report

Static analysis result for SHA-256 887a7ed09d746553…

MALICIOUS

PDF

22.1 KB Created: 2019-05-07 08:24:45 +01:00 Authoring application: mPDF 5.7
MD5: 7434790ea0837f0749e6948942ac6867 SHA-1: b6c6c3bd6d12f6c16ee4f179e3ba2f585ca1b073 SHA-256: 887a7ed09d746553823561fff2dc771b7274e08d67b533e724abc33bcdb92b6c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a link farm designed to direct users to external content, potentially for SEO manipulation or to host malicious payloads. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a03a08a02a06/The-Thing-Itself-by-Adam-Roberts.pdf
    • http://muicuiu.dumb1.com/2a06a06a07a05/Jack-Glass-by-Adam-Roberts.pdf
    • http://muicuiu.dumb1.com/3a09a06a01a03a09/Yellow-Blue-Tibia-by-Adam-Roberts.pdf
    • http://muicuiu.dumb1.com/3a07a08a02a04a08/Toes-Up-Horror-to-Die-For-by-Adam-Light.pdf
    • http://muicuiu.dumb1.com/1a02a02a08a06/Key-of-Light-Key-Trilogy-1-by-Nora-Roberts.pdf
    • http://muicuiu.dumb1.com/9a01a05a01a09a01/Key-Of-Light-Morrigan-s-Cross-by-Nora-Roberts.pdf
    • http://muicuiu.dumb1.com/1a00a03a02a07a04/Civil-Resistance-and-Power-Politics-The-Experience-of-Non-Violent-Action-from-Gandhi-to-the-Present-by-Adam-Roberts.pdf
    • http://muicuiu.dumb1.com/2a04a05a07a05a01/How-Adam-Smith-Can-Change-Your-Life-An-Unexpected-Guide-to-Human-Nature-and-Happiness-by-Russ-Roberts.pdf
    • http://muicuiu.dumb1.com/4a07a09a08a02a08/GEDLA-ADAM-The-Combat-of-Adam-Against-Satan-The-Book-of-Adam-amp-Eve-by-Ethiopian-Church.pdf
    • http://muicuiu.dumb1.com/4a07a04a08a09a05/Mastering-Composition-Techniques-and-Principles-to-Dramatically-Improve-Your-Painting-Mastering-North-Light-Books-by-Ian-Roberts.pdf
    • http://muicuiu.dumb1.com/2a03a04a01a02a05/The-Invasion-of-Adam-Tork-and-Adam-2-by-Claire-Davis.pdf
    • http://muicuiu.dumb1.com/2a08a00a07a08a03/Eve-amp-Adam-Eve-amp-Adam-1-by-Michael-Grant.pdf
    • http://muicuiu.dumb1.com/9a07a07a00a03/Out-in-the-Dark-Poetry-of-the-First-World-War-in-Context-and-with-Basic-Notes-David-Roberts-by-David---Roberts.pdf
    • http://muicuiu.dumb1.com/4a08a08a00a08a06/Traitor-s-Knot-Wars-of-Light-amp-Shadow-7-Arc-3---Alliance-of-Light-4-by-Janny-Wurts.pdf
    • http://muicuiu.dumb1.com/3a04a02a08a06a06/Fugitive-Prince-Wars-of-Light-amp-Shadow-4-Arc-3---Alliance-of-Light-1-by-Janny-Wurts.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a00a02a02/Light-Fighter-A-Devotional-Guide-for-Soliers-and-All-Who-Fight-for-the-Light-by-James-M-Fogle-Miller.pdf
    • http://muicuiu.dumb1.com/8a01a03a03a01a00/Light-of-the-Shadow-When-that-s-left-is-Darkness-only-her-Light-can-save-him-Gaea-Book-3-by-Sopha-CarPerSanti.pdf
    • http://muicuiu.dumb1.com/7a00a07a04a06a03/Adam-Smith-Great-Books-of-the-Western-World-36-by-Adam-Smith.pdf
    • http://muicuiu.dumb1.com/1a09a05a02a01a03/Adam-Undercover-The-Presidium-Files-Adam-Undercover-1-by-Aaron-Foster.pdf
    • http://muicuiu.dumb1.com/3a06a02a00a03a07/Light-from-Light-An-Anthology-of-Christian-Mysticism-by-Louis-Dupr-.pdf
    • http://muicuiu.dumb1.com/2a04a05a07a05a01/How-Adam-Smi