Malicious PDF — malware analysis report

Static analysis result for SHA-256 94f0de79bf5b9279…

MALICIOUS

PDF

31.4 KB Created: 2019-04-30 02:46:15 +01:00 Authoring application: mPDF 5.7
MD5: c689b39d56d2b8cf95b51db444822af1 SHA-1: 52957f2f13ecf0fb0d8fcfd1ad9bb3f63140a387 SHA-256: 94f0de79bf5b92795a6aa172682eb7ca351fcb8b27ef3a7aa81daabdbb9e2bf6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that this is a technique to potentially distribute malicious content or engage in SEO abuse. While the document body is heavily obfuscated, the presence of numerous links suggests a deceptive attempt to redirect users to external resources. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9689

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a00a03a01a02a09/Christmas-Carols-Ancient-and-Modern-Including-the-Most-Popular-in-the-West-of-England-and-the-Airs-to-Which-They-Are-Sung-Also-Specimens-of-French-Provincial-Carols-with-an-Introduction-and-Notes-by-William-Sandys.pdf
    • http://muicuiu.dumb1.com/8a00a05a04a04a02/A-Christmas-Carol-Victorian-Carols-with-Readings-from-Dickens-by-Charles-Dickens.pdf
    • http://muicuiu.dumb1.com/7a05a05a03a00a04/Carols-We-Love-Your-Favorite-Composers-Share-a-Few-of-Their-Favorites-by-Pepper-Choplin.pdf
    • http://muicuiu.dumb1.com/5a01a03a03a04a05/The-Memory-of-the-People-Custom-and-Popular-Senses-of-the-Past-in-Early-Modern-England-by-Andy-Wood.pdf
    • http://muicuiu.dumb1.com/7a09a05a09a07a00/Macbeth-Ed-with-Notes-and-an-Introduction-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a04a09a00a04a04/The-Merchant-of-Venice---with-introduction-notes-and-questions-for-review-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a04a09a00a04a03/Julius-Caesar-With-Introduction-Notes-and-Questions-for-Review-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/7a03a01a08a05a09/The-Couple-s-Tao-Te-Ching-Ancient-Advice-for-Modern-Lovers-by-William-Martin.pdf
    • http://muicuiu.dumb1.com/1a00a08a08a02a03a09/Origins-The-Ancient-Near-Eastern-Background-Of-Some-Modern-Western-Institutions-by-William-W-Hallo.pdf
    • http://muicuiu.dumb1.com/1a00a07a05a06a09a02/The-Poetical-Works-of-Thomas-Moore-Including-Lalya-Rookh-Odes-of-Anacreon-Irish-Melodies-National-Airs-and-Miscellaneous-Poems-by-Thomas-Moore.pdf
    • http://muicuiu.dumb1.com/6a03a00a03a09a03/French-History-Introduction-Berry-Douane-Lacan-Treaty-of-Tours-Louis-the-Stammerer-Coutumes-de-Beauvaisis-French-Ship-Redoutable-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/1a01a07a08a02a03a02/Ancient-Bronzes-through-a-Modern-Lens-Introductory-Essays-on-the-Study-of-Ancient-Mediterranean-and-Near-Eastern-Bronzes-by-Susanne-Ebbinghaus.pdf
    • http://muicuiu.dumb1.com/1a01a00a00a03a01/Inventing-the-People-The-Rise-of-Popular-Sovereignty-in-England-and-America-by-Edmund-S-Morgan.pdf
    • http://muicuiu.dumb1.com/5a03a04a06a04a09/A-Very-French-Christmas-The-Greatest-French-Holiday-Stories-of-All-Time-by-Guy-de-Maupassant.pdf
    • http://muicuiu.dumb1.com/7a04a07a08a06a05/Nautical-Terms-in-English-and-French-and-French-and-English-With-Notes-and-Tables-by-Leon-Delbos.pdf
    • http://muicuiu.dumb1.com/2a00a00a01a05a00/Worlds-of-Wonder-Days-of-Judgment-Popular-Religious-Belief-in-Early-New-England-by-David-D-Hall.pdf
    • http://muicuiu.dumb1.com/1a00a02a05a06a09a05/The-Contemporary-French-Writers-Selections-from-the-French-Writers-of-the-Second-Part-of-the-19th-Century-with-Literary-Notices-and-Historical-Geographical-Etymological-Grammatical-and-Explanatory-Notes-by-Rosine-Melle.pdf
    • http://muicuiu.dumb1.com/1a01a05a03a07a09a01/Introduction-to-Maat-Philosophy-Introduction-to-Maat-Philosophy-Ancient-Egyptian-Ethics-amp-Metaphysics-by-Muata-Ashby.pdf
    • http://muicuiu.dumb1.com/6a07a04a09a09a01/Ancient-England-by-Nigel-Blundell.pdf
    • http://muicuiu.dumb1.com/1a00a00a08a08/Popular-Vintage-Wisdom-for-a-Modern-Geek-by-Maya-Van-Wagenen.pdf