Malicious PDF — malware analysis report

Static analysis result for SHA-256 9017846f901078cb…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 04:12:11 +01:00 Authoring application: mPDF 5.7
MD5: 2d6d107ba229cfd260daee8a7a6aed94 SHA-1: 89a859be770e3b0987a9662a356f34fe9ac42503 SHA-256: 9017846f901078cbbba6ecda1e44cdc28f0dbecbf9b5dc58dbda090a16beea6b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While most of these specific URLs were labeled as confirmed_benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a07a06a06a04/Bunny-Mellon-The-Life-of-an-American-Style-Legend-by-Meryl-Gordon.pdf
    • http://muicuiu.dumb1.com/5a01a03a08a02a03/Black-Maestro-The-Epic-Life-of-an-American-Legend-by-Joe-Drape.pdf
    • http://muicuiu.dumb1.com/4a02a05a04a04a09/American-Legend-The-Real-Life-Adventures-of-David-Crockett-by-Buddy-Levy.pdf
    • http://muicuiu.dumb1.com/1a04a03a09a06a03/The-Man-Called-CASH-The-Life-Love-and-Faith-of-an-American-Legend-by-Steve-Turner.pdf
    • http://muicuiu.dumb1.com/1a01a04a02a05a03/Fatal-Mountaineer-The-High-Altitude-Life-and-Death-of-Willi-Unsoeld-American-Himalayan-Legend-by-Robert-Roper.pdf
    • http://muicuiu.dumb1.com/1a01a04a01a09a04a07/Black-Moon-The-legend-of-Pango-marama-by-Ken-Gordon.pdf
    • http://muicuiu.dumb1.com/4a00a04a03a02a05/Bunny-Bunny-Gilda-Radner-A-Sort-of-Love-Story-by-Alan-Zweibel.pdf
    • http://muicuiu.dumb1.com/1a00a02a07a05a07a07/Lord-and-Lady-Bunny--Almost-Royalty-The-Bunny-s-2-by-Polly-Horvath.pdf
    • http://muicuiu.dumb1.com/1a01a08a00a09a08a09/Sushi-American-Style-by-Tracy-Griffith.pdf
    • http://muicuiu.dumb1.com/9a09a05a05a09a01/American-Bungalow-Style-by-Robert-Winter.pdf
    • http://muicuiu.dumb1.com/9a09a05a07a04a08/Bungalow-American-Restoration-Style-by-Jan-Cigliano.pdf
    • http://muicuiu.dumb1.com/3a01a06a05a01a02/It-s-Happy-Bunny-Life-Get-One-by-Jim-Benton.pdf
    • http://muicuiu.dumb1.com/1a05a09a01a04a05/My-Life-as-a-Snow-Bunny-by-Kaz-Delaney.pdf
    • http://muicuiu.dumb1.com/4a01a07a05a02a09/Where-Did-Bunny-Go-A-Bunny-and-Bird-Story-by-Nancy-Tafuri.pdf
    • http://muicuiu.dumb1.com/6a02a07a00a01a09/A-World-Elsewhere-The-Place-of-Style-in-American-Literature-by-Richard-Poirier.pdf
    • http://muicuiu.dumb1.com/4a05a08a05a05a09/32-Third-Graders-and-One-Class-Bunny-Life-Lessons-from-Teaching-by-Phillip-Done.pdf
    • http://muicuiu.dumb1.com/4a05a01a04a08a00/To-Be-with-You-Sunset-1-by-Opal-Mellon.pdf
    • http://muicuiu.dumb1.com/9a01a00a05a08a04/In-My-Shoes-A-Memoir-by-Tamara-Mellon.pdf
    • http://muicuiu.dumb1.com/3a07a00a06a04a05/Seabiscuit-An-American-Legend-by-Laura-Hillenbrand.pdf
    • http://muicuiu.dumb1.com/2a01a06a07a02/Seabiscuit-An-American-Legend-by-Laura-Hillenbrand.pdf
    • http://muicuiu.dumb1.com/1a