Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ed6e5248dcc7469…

MALICIOUS

PDF

13.9 KB Created: 2019-04-30 03:30:32 +01:00 Authoring application: mPDF 5.7
MD5: d423d2da298942093d1633c78b9b49ef SHA-1: 135d03e3f81fba64de5daca316d842a253f9e205 SHA-256: 8ed6e5248dcc7469577c0d8535b377c1c98eecfbd2e8fe5cce3e763d39a69b16
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO spam or to redirect users to malicious sites. No scripts were extracted, and the document body was heavily obfuscated, preventing a more detailed analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a01a00a05a09/Keegan-s-Lady-Keegan-Paxton-1-by-Catherine-Anderson.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a04a03/Scent-of-a-White-Rose-The-Rose-Trilogy-1-by-Tish-Thawer.pdf
    • http://muicuiu.dumb1.com/1a03a01a06a07a03/Scent-of-a-White-Rose-The-Rose-Trilogy-1-by-Tish-Thawer.pdf
    • http://muicuiu.dumb1.com/4a05a01a06a04a09/The-White-Rose-by-Mary-Ann-Cook.pdf
    • http://muicuiu.dumb1.com/2a06a03a03a00a02/Snow-White-and-Rose-Red-by-Ed-McBain.pdf
    • http://muicuiu.dumb1.com/2a09a07a06a02a05/White-Rose-Rebel-by-Janet-Paisley.pdf
    • http://muicuiu.dumb1.com/5a00a05a08a09a05/White-Locks-Colorblind-2-by-Rose-B-Mashal.pdf
    • http://muicuiu.dumb1.com/3a01a06a05a03a06/NIGHT-ORACLE-by-J-P-Rose.pdf
    • http://muicuiu.dumb1.com/6a08a05a06a00a04/Night-of-the-Fete-by-V-S-Rose.pdf
    • http://muicuiu.dumb1.com/1a02a02a00a08a08/Sword-of-the-White-Rose-Mathesons-Book-4-by-J-Ardian-Lee.pdf
    • http://muicuiu.dumb1.com/2a07a03a06a08a04/White-Buffalo-Calf-Warriors-by-Rose-Christo.pdf
    • http://muicuiu.dumb1.com/2a06a02a06a05/Black-Thorn-White-Rose-by-Ellen-Datlow.pdf
    • http://muicuiu.dumb1.com/4a08a09a01a09a09/Secret-of-the-White-Rose-Simon-Ziele-3-by-Stefanie-Pintoff.pdf
    • http://muicuiu.dumb1.com/2a00a04a09a06a05/Snow-White-and-Rose-Red-The-Curse-of-the-Huntsman-by-Lilly-Fang.pdf
    • http://muicuiu.dumb1.com/9a00a08a07a07a05/The-White-Rose-of-Nightfall-Clan-of-Kelly-1-by-Carla-Peele.pdf
    • http://muicuiu.dumb1.com/3a02a00a07a06a08/Rose-Red-amp-Snow-White-A-Grimms-Fairy-Tale-by-Ruth-Sanderson.pdf
    • http://muicuiu.dumb1.com/4a03a01a09a08a01/Ghouls-Night-Out-Larue-Donavan-2-by-Rose-Pressey.pdf
    • http://muicuiu.dumb1.com/3a03a06a06a01a00/In-The-Night--A-Paranormal-Mystery-Short-by-Lexie-Rose.pdf
    • http://muicuiu.dumb1.com/3a06a09a04a02a02/Night-Moves-The-Doms-of-Sybaris-Cove-6-by-Tara-Rose.pdf
    • http://muicuiu.dumb1.com/1a07a09a07a02a06/A-Night-with-the-Rock-Star-Taking-Stage-2-by-Emma-Rose.pdf