Malicious PDF — malware analysis report

Static analysis result for SHA-256 92d4af760bee1854…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 02:08:38 +01:00 Authoring application: mPDF 5.7
MD5: 7ebae05bcbd6cf40ec956fad6b790f1f SHA-1: 439810142e434caf8ee41220feb7c833370723e5 SHA-256: 92d4af760bee1854175a4f374b1d407475f884c4d4b775810ba051a9d800109b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that this is a technique to distribute malicious content or engage in SEO abuse. While the specific URLs extracted were labeled as benign, the overall structure and the ML classifier's high confidence score suggest a malicious intent, likely to redirect users to harmful content or phishing sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu
    • http://muicuiu.dumb1.com/1a00a06a05a00a05a02/Tempted-By-You-Destiny-Bay-Romances-The-Islanders-3-by-Helen-Conrad.pdf
    • http://muicuiu.dumb1.com/1a00a06a04a09a08a03/Saved-By-You-Destiny-Bay-The-Islanders-1-by-Helen-Conrad.pdf
    • http://muicuiu.dumb1.com/1a00a06a05a01a04a06/Amazed-By-You-Destiny-Bay-The-Islanders-6-by-Helen-Conrad.pdf
    • http://muicuiu.dumb1.com/4a00a01a09a00a05/Islanders-by-Helen-R-Hull.pdf
    • http://muicuiu.dumb1.com/1a00a06a05a00a05a05/The-Islanders-by-Helen-Dunmore.pdf
    • http://muicuiu.dumb1.com/3a07a03a09a03a08/Bloodlust-Blood-Destiny-5-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/2a02a00a04a05a04/Bloodrage-Blood-Destiny-3-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/2a07a07a05a01a06/Bloodmagic-Blood-Destiny-2-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/7a03a00a06a05a02/Character-in-the-Matter-of-England-romances-part-of-a-thesis-entitled-A-study-of-the-narrative-art-of-four-metrical-romances-by-Herbert-Le-Sourd-Creek.pdf
    • http://muicuiu.dumb1.com/2a00a06a06a03a08/Tempted-Tempted-1-by-Elizabeth-Kelly.pdf
    • http://muicuiu.dumb1.com/2a02a03a03a02/They-Call-Me-Destiny-by-Destiny-Kalser-with-Fern-Field-Brooks.pdf
    • http://muicuiu.dumb1.com/3a08a01a07a06a01/Dark-Destiny-Destiny-Novella-Trilogy-1-by-Kari-Gray.pdf
    • http://muicuiu.dumb1.com/2a01a08a07a09a05/Cherishing-Destiny-A-Dangerous-Destiny-1-by-Noelle-Blakely.pdf
    • http://muicuiu.dumb1.com/3a09a08a05a03a04/Destiny-s-Choice-Destiny-s-Series-2-by-Victoria-Saccenti.pdf
    • http://muicuiu.dumb1.com/2a04a09a09a01a00/Destiny-Divided-Shadows-of-Destiny-1-by-Leia-Shaw.pdf
    • http://muicuiu.dumb1.com/1a04a05a01a07a06/Destiny-s-Embrace-Destiny-1-by-Beverly-Jenkins.pdf
    • http://muicuiu.dumb1.com/3a07a04a00a00a08/Christmas-in-Destiny-Destiny-7-by-Toni-Blake.pdf
    • http://muicuiu.dumb1.com/3a09a08a03a03a02/Destiny-s-Way-Destiny-s-Series-3-by-Victoria-Saccenti.pdf
    • http://muicuiu.dumb1.com/1a08a06a06a02a05/Helen-s-Eyes-A-Photobiography-of-Annie-Sullivan-Helen-Keller-s-Teacher-by-Marfe-Ferguson-Delano.pdf
    • http://muicuiu.dumb1.com/1a00a06a05a00a09a06/The-Islanders-by-Amy-Mason.pdf