Malicious PDF — malware analysis report

Static analysis result for SHA-256 8eb9deb5c90168dc…

MALICIOUS

PDF

20.6 KB Created: 2019-05-01 14:15:42 +01:00 Authoring application: mPDF 5.7
MD5: 261e3bb1d37d9a301af5a957519f0743 SHA-1: f3b254bfe55f3c8632ddfe1dbbb2d2ba02f43bf8 SHA-256: 8eb9deb5c90168dc748ec01c56a6344a376091685532acc6f46ed110acb9dd1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a PDF_SEO_LINK_FARM heuristic firing, indicating the presence of a large number of embedded external links. These links, such as http://muicuiu.dumb1.com/6a06a05a04a03a03/Cantates-Le-Berger-Fidele-Air-Gai-and-recitatif-by-Jean-Philippe-Rameau.pdf, are likely used to distribute further malicious content or for SEO manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a06a05a04a03a03/Cantates-Le-Berger-Fidele-Air-Gai-and-recitatif-by-Jean-Philippe-Rameau.pdf
    • http://muicuiu.dumb1.com/5a09a03a07a05a04/Soupirs-Les---No-17-from-quot-Pieces-de-clavecin-quot-1724-by-Jean-Philippe-Rameau.pdf
    • http://muicuiu.dumb1.com/1a00a06a04a07a09a04/Het-quot-Traite-de-L-Harmonie-quot-1722-Van-Jean-Philippe-Rameau-En-de-Ontwikkeling-Van-Het-Muziektheoretische-Denken-in-Frankrijk-by-Jan-Caeyers.pdf
    • http://muicuiu.dumb1.com/3a02a08a09a01a04/The-Bathroom-by-Jean-Philippe-Toussaint.pdf
    • http://muicuiu.dumb1.com/2a03a07a02/The-6-41-to-Paris-by-Jean-Philippe-Blondel.pdf
    • http://muicuiu.dumb1.com/5a01a02a03a07a00/Running-Away-by-Jean-Philippe-Toussaint.pdf
    • http://muicuiu.dumb1.com/6a00a01a06a08a08/Making-Love-by-Jean-Philippe-Toussaint.pdf
    • http://muicuiu.dumb1.com/7a06a01a04a00/The-Truth-About-Marie-by-Jean-Philippe-Toussaint.pdf
    • http://muicuiu.dumb1.com/6a07a07a08a02a07/R-veil-ultra-matinal-by-Jean-Philippe-Touzeau.pdf
    • http://muicuiu.dumb1.com/7a05a03a02a09a06/Valuing-the-Environment-Six-Case-Studies-by-Jean-Philippe-Barde.pdf
    • http://muicuiu.dumb1.com/8a03a05a01a04a01/Institutions-Social-Norms-and-Economic-Development-by-Jean-Philippe-Platteau.pdf
    • http://muicuiu.dumb1.com/7a05a03a02a08a05/Transport-Policy-and-the-Environment-Six-Case-Studies-by-Jean-Philippe-Barde.pdf
    • http://muicuiu.dumb1.com/7a08a07a01a05a06/L-vidence-La-certitude-absolue-que-chaque-chose-a-un-sens-by-Jean-Philippe-Br-bion.pdf
    • http://muicuiu.dumb1.com/7a09a02a09a09a05/Les-5-Cercueils-de-L-Empereur-Souvenirs-Inedits-de-Philippe-de-Rohan-Chabot-Commissaire-Du-Roi-Louis-Philippe-by-Philippe-Ferdinand-Auguste-de-Rohan-Chabot-Jarnac.pdf
    • http://muicuiu.dumb1.com/8a03a05a01a04a02/Is-Islam-a-Special-Problem-Exploring-the-Link-Between-Religion-Politics-and-Development-by-Jean-Philippe-Platteau.pdf
    • http://muicuiu.dumb1.com/6a07a07a05a01a04/Maigrir-avec-la-lune-Faites-fondre-vos-kilos-superflus-en-suivant-les-cycles-lunaires-de-Carole-Berger-by-Carole-Berger.pdf
    • http://muicuiu.dumb1.com/7a00a00a09a05a01/Berger-on-Drawing-by-John-Berger.pdf
    • http://muicuiu.dumb1.com/7a06a01a00a06a02/Diderot-the-Satirist-Le-neveu-de-Rameau-amp-Related-Works-An-Analysis-by-Donal-O-39-Gorman.pdf
    • http://muicuiu.dumb1.com/6a06a05a03a01a09/Fidele-the-Legend-of-a-Good-Dog-by-Mary-E-Little.pdf
    • http://muicuiu.dumb1.com/6a06a05a03a04a07/Une-femme-fid-le-by-Bruno-Cheilme.pdf