Malicious PDF — malware analysis report

Static analysis result for SHA-256 887d9e57c9c548dc…

MALICIOUS

PDF

23.6 KB Created: 2019-04-30 06:12:30 +01:00 Authoring application: mPDF 5.7
MD5: dcbd2501213fc719ca64b553f34c7db7 SHA-1: 6dc72e3e8889710b2271307c45a44af85c2df8c7 SHA-256: 887d9e57c9c548dcce0ddfbd7b07c84c07649509e26034c359d6a3a92856bc6b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links, forming a link farm. The primary heuristic indicates this is a "PDF_SEO_LINK_FARM" with 32 links, suggesting a malicious intent to redirect users. While the document body is heavily obfuscated, the structure and the link farm pattern are indicative of a phishing or redirection attempt. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a09a01a05a05a07/Librarian-Spies-Philip-and-Mary-Jane-Keeney-and-Cold-War-Espionage-by-Rosalee-McReynolds.pdf
    • http://muicuiu.dumb1.com/1a00a09a08a01a04a03/Spies-Espionage-and-Covert-Operations-From-Ancient-Greece-to-the-Cold-War-by-Michael-Rank.pdf
    • http://muicuiu.dumb1.com/3a03a06a02a01a00/The-New-Spymasters-Inside-Espionage-from-the-Cold-War-to-Global-Terror-by-Stephen-Grey.pdf
    • http://muicuiu.dumb1.com/3a04a08a09a07a05/The-Billion-Dollar-Spy-A-True-Story-of-Cold-War-Espionage-and-Betrayal-by-David-E-Hoffman.pdf
    • http://muicuiu.dumb1.com/1a02a03a06/The-Billion-Dollar-Spy-A-True-Story-of-Cold-War-Espionage-and-Betrayal-by-David-E-Hoffman.pdf
    • http://muicuiu.dumb1.com/8a09a01a06a00a03/Wells-of-Glory-by-Mary-McReynolds.pdf
    • http://muicuiu.dumb1.com/1a06a01a09a04a05/How-the-Cold-War-Began-The-Gouzenko-Affair-and-the-Hunt-for-Soviet-Spies-by-Amy-Knight.pdf
    • http://muicuiu.dumb1.com/8a01a07a04a05a09/Spies-in-the-Family-An-American-Spymaster-His-Russian-Crown-Jewel-and-the-Friendship-That-Helped-End-the-Cold-War-by-Eva-Dillon.pdf
    • http://muicuiu.dumb1.com/8a09a01a05a09a00/The-Tapeworm-Emails-and-the-Gloria-Airmails-The-Flip-Side-of-Temptation-by-Mary-McReynolds.pdf
    • http://muicuiu.dumb1.com/3a03a06a02a00a02/Wellington-S-Spies-by-Mary-McGrigor.pdf
    • http://muicuiu.dumb1.com/6a01a03a02a01/Cold-Case-by-Philip-Gourevitch.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a08a04/Dear-Ellen-Bee-A-Civil-War-Scrapbook-of-Two-Union-Spies-by-Mary-E-Lyons.pdf
    • http://muicuiu.dumb1.com/2a05a02a00a09a05/Persuasion-Captain-Wentworth-and-Cracklin-Cornbread-Jane-Austen-Takes-the-South-3-by-Mary-Jane-Hathaway.pdf
    • http://muicuiu.dumb1.com/8a09a01a05a05a09/Larry-McReynolds-My-Life-from-Pit-Road-to-the-Broadcast-Booth-by-Larry-Mcreynolds.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a06a09a01/Spies-Among-Us-How-to-Stop-the-Spies-Terrorists-Hackers-and-Criminals-You-Don-t-Even-Know-You-Encounter-Every-Day-by-Ira-Winkler.pdf
    • http://muicuiu.dumb1.com/4a06a03a07a02a01/Conan-the-Librarian-Conan-the-Librarian-1-by-Tara-Luebbe.pdf
    • http://muicuiu.dumb1.com/2a06a05a09a05a02/Cold-Reign-Jane-Yellowrock-11-by-Faith-Hunter.pdf
    • http://muicuiu.dumb1.com/1a01a00a05a05a05a06/The-Science-of-Philip-Pullman-s-His-Dark-Materials-by-Mary-Gribbin.pdf
    • http://muicuiu.dumb1.com/2a02a02a00a03a07/Primavera-by-Mary-Jane-Beaufrand.pdf
    • http://muicuiu.dumb1.com/1a00a00a09a07a08a05/Guitar-Boy-by-Mary-Jane-Auch.pdf