Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dbe540983419fc9…

MALICIOUS

PDF

13.2 KB Created: 2019-04-30 04:29:07 +01:00 Authoring application: mPDF 5.7
MD5: 1af57f66dabceed3cfb5a928e9b192dc SHA-1: 8bd2b84efce6fa97a270c7ba1a9cc0c543c29081 SHA-256: 9dbe540983419fc9ec374bae8763e2b7a99c46ef2c9b9e6fef3da31d16b20669
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a05a02a02a06a07/Sharpe-s-Waterloo-Sharpe-20-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/3a01a04a03a08a06/Sharpe-s-Rifles-Sharpe-6-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/7a04a01a01a05/Sharpe-s-Tiger-Sharpe-1-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a00a08a09a00/Sharpe-s-Escape-Sharpe-10-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a09a00a08a04/Sharpe-s-Triumph-Sharpe-2-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a09a01a03a07/Sharpe-s-Enemy-Sharpe-15-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/6a05a03a01a00/Sharpe-s-Company-Sharpe-13-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/8a04a00a04a07/Sharpe-s-Regiment-Sharpe-17-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a00a09a03a00/Sharpe-s-Havoc-Sharpe-7-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a09a01a09a00/Sharpe-s-Trafalgar-Sharpe-4-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a09a01a06a02/Sharpe-s-Revenge-Sharpe-19-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a04a09a03a05a06/Sharpe-s-Fortress-Sharpe-3-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/8a07a03a06a04a06/Sharpes-Feind-Sharpe-Band-15-by-Bernard-Cornwell.pdf
    • http://muicuiu.dumb1.com/1a01a04a09a02a02a05/They-Also-Serve-by-Bob-Sharpe.pdf
    • http://muicuiu.dumb1.com/2a04a08a09a04a04/Far-from-You-by-Tess-Sharpe.pdf
    • http://muicuiu.dumb1.com/1a07a07a08a06a08/The-Throwback-by-Tom-Sharpe.pdf
    • http://muicuiu.dumb1.com/1a08a03a07a04a05/At-the-Sharpe-End-by-Hugh-Ashton.pdf
    • http://muicuiu.dumb1.com/3a07a01a06a00a04/Bound-To-The-Billionaire-by-Rod-Sharpe.pdf
    • http://muicuiu.dumb1.com/2a09a04a03a04a03/Vintage-Stuff-by-Tom-Sharpe.pdf
    • http://muicuiu.dumb1.com/3a07a09a01a06/Fresh-by-Dennis-Sharpe.pdf
    • http://muicuiu.dumb1.com/1a04a09a03a05a06/Sharpe-s-Fortress-Sharpe-3-by-Bernard-Corn