Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ed15d03f9388043…

MALICIOUS

PDF

31.7 KB Created: 2019-05-02 01:20:45 +01:00 Authoring application: mPDF 5.7
MD5: 9aca035469f470f5295cfd4417e43f32 SHA-1: 6c7747ed772408642b515180ba222deb77156c24 SHA-256: 8ed15d03f9388043fc2159dc9404edd0e97960ab4ae125dbb8e41da85e5f1586
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a05a06a02a08a01/Special-Catalogue-of-the-Royal-Museums-at-Berlin-A-the-Old-Museum-by-Wassermann.pdf
    • http://muicuiu.dumb1.com/9a04a04a07a02a03/Judisches-Museum-Judisches-Museum-in-Deutschland-Judisches-Museum-Westfalen-Judisches-Museum-Berlin-Schrein-Des-Buches-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/6a03a02a05a01a00/History-of-Berlin-Ich-Bin-Ein-Berliner-Wannsee-Conference-Berlin-Wall-West-Berlin-East-Berlin-Nikolaiviertel-Berlin-Blockade-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a08a09a07a02/Samuel-P-Harn-Museum-of-Art-at-Twenty-Years-The-Collection-Catalogue-by-Jason-Steuber.pdf
    • http://muicuiu.dumb1.com/8a00a08a00a07a02/Catalogue-of-the-Pictures-Miniatures-Pastels-Framed-Water-Colour-Drawings-Etc-in-the-Rijks-Museum-at-Amsterdam-by-Rijksmuseum.pdf
    • http://muicuiu.dumb1.com/5a08a09a09a07a02/Education-in-Mali-Malian-Academics-Museums-in-Mali-National-Museum-of-Mali-Ahmad-Baba-Al-Massufi-Sidi-Yahya-Mosque-Sidib-Aminata-Diallo-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a07a07a06/Hamburg-Bahnhof-Museum-for-the-Present-Berlin-by-Penelope-Crowe.pdf
    • http://muicuiu.dumb1.com/8a00a08a00a03a03/Catalogue-of-the-Pictures-Miniatures-Pastels-Framed-Drawings-Etc-in-the-Rijks-Museum-at-Amsterdam-with-Supplement-by-Rijksmuseum-Rijksmuseum.pdf
    • http://muicuiu.dumb1.com/8a07a03a01a04a08/James-Ensor-Collection-of-the-Royal-Museum-of-Fine-Arts-Antwerp-by-Herwig-Todts.pdf
    • http://muicuiu.dumb1.com/1a00a01a03a04a03a05/Berlin-Kreuzberg-Deutsches-Technikmuseum-Berlin-Landwehrkanal-Liste-Der-Strassen-Und-Platze-in-Berlin-Kreuzberg-Berlin-Anhalter-Bahnhof-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a04a04a07a02a04/Judisches-Museum-in-Deutschland-Judisches-Museum-in-Baden-Wurttemberg-Judisches-Museum-in-Bayern-Judisches-Museum-in-Rheinland-Pfalz-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a08a04a05/U-Bahnhof-in-Berlin-Bahnhof-Berlin-Zoologischer-Garten-Bahnhof-Berlin-Lichtenberg-Liste-Der-Berliner-U-Bahnhofe-Berlin-Hauptbahnhof-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a01a09a08a05a07a07/Olaf-Nicolai---Sammlers-Blick-A-Catalogue-A-Catalogue-by-Boris-Groys.pdf
    • http://muicuiu.dumb1.com/3a08a04a08a03a01/Treasures-of-Early-Irish-Art-1500-BC-to-1500-AD-from-the-Collections-of-the-National-Museum-of-Ireland-Royal-Irish-Academy-Trinity-College-Dublin-by-Polly-Cone.pdf
    • http://muicuiu.dumb1.com/6a03a09a09a00a07/Native-Studies-Collection-Catalogue-La-Collection-Des-Etudes-Autochtones-Catalogue-by-Canadian-Institute-for-Historical-Micror.pdf
    • http://muicuiu.dumb1.com/1a02a04a03a01a06/How-to-Build-a-Museum-Smithsonian-s-National-Museum-of-African-American-History-and-Culture-by-Tonya-Bolden.pdf
    • http://muicuiu.dumb1.com/1a00a02a05a07a03a06/New-National-Gallery-Berlin-Berlin-1962-68-Ludwig-Mies-Van-Der-Rohe-by-Maritz-Vandenberg.pdf
    • http://muicuiu.dumb1.com/4a04a08a06a08/The-Berlin-Stories-The-Last-of-Mr-Norris-Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/3a04a03a04a00a09/The-Berlin-Stories-The-Last-of-Mr-Norris-amp-Goodbye-to-Berlin-by-Christopher-Isherwood.pdf
    • http://muicuiu.dumb1.com/1a07a09a03a03/Museum-of-Flight-100-Years-of-Aviation-History-From-the-Wright-Bros-to-the-Moon-by-Museum-of-Flight.pdf
    • http://muicuiu.dumb1.com/