Malicious PDF — malware analysis report

Static analysis result for SHA-256 9eb02411dba42c29…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 06:03:05 +01:00 Authoring application: mPDF 5.7
MD5: 3d10b9f2cf53d88118cae131f3dd37ce SHA-1: e4a2e02b9163e33de86e41d947d56c1ebce6cbd8 SHA-256: 9eb02411dba42c298088598bdd37cc07109c1617eccea7edbe4da212aa931f84
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, possibly to manipulate search engine results or to serve as a lure for further malicious activity. The document body itself is heavily obfuscated and contains repeated URLs, reinforcing the link-farming behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a04a01a04a02a08/Unmaking-Goliath-Community-Control-in-the-Face-of-Global-Capital-by-James-DeFilippis.pdf
    • http://muicuiu.dumb1.com/4a08a02a02a05/The-World-Of-Patience-Gromes-Making-And-Unmaking-A-Black-Community-by-Scott-C-Davis.pdf
    • http://muicuiu.dumb1.com/8a02a07a08a08a02/Civilising-Global-Capital-New-Thinking-for-Australian-Labor-by-Mark-Latham.pdf
    • http://muicuiu.dumb1.com/7a01a00a07a02a04/Sufism-Today-Heritage-and-Tradition-in-the-Global-Community-by-Catharina-Raudvere.pdf
    • http://muicuiu.dumb1.com/7a07a01a01a09a03/Community-Colleges-Worldwide-Investigating-the-Global-Phenomenon-17-by-Alexander-W-Wiseman.pdf
    • http://muicuiu.dumb1.com/8a04a01a08a05a03/Alibaba-s-World-How-a-Remarkable-Chinese-Company-is-Changing-the-Face-of-Global-Business-by-Porter-Erisman.pdf
    • http://muicuiu.dumb1.com/5a09a05a09a08a09/The-Making-and-Unmaking-of-Empires-Britain-India-and-America-C-1750-1783-by-Peter-James-Marshall.pdf
    • http://muicuiu.dumb1.com/5a03a09a01a03a09/Le-Capital-Tome-1-Le-proc-s-de-production-du-capital-by-Karl-Marx.pdf
    • http://muicuiu.dumb1.com/8a04a09a09a06a02/Capital-New-York-Capital-of-the-20th-Century-by-Kenneth-Goldsmith.pdf
    • http://muicuiu.dumb1.com/3a03a06a03a03a03/Cover-Her-Face-Adam-Dalgliesh-1-by-P-D-James.pdf
    • http://muicuiu.dumb1.com/1a00a06a00a08a05a00/North-Face-of-Soho-by-Clive-James.pdf
    • http://muicuiu.dumb1.com/2a05a01a03a03a04/Cover-Her-Face-Adam-Dalgliesh-1-by-P-D-James.pdf
    • http://muicuiu.dumb1.com/1a00a09a08a07a05/Captives-and-Cousins-Slavery-Kinship-and-Community-in-the-Southwest-Borderlands-by-James-F-Brooks.pdf
    • http://muicuiu.dumb1.com/2a06a02a00a04a01/The-Vanishing-Face-of-Gaia-A-Final-Warning-by-James-E-Lovelock.pdf
    • http://muicuiu.dumb1.com/6a00a06a01a03a06/Cover-Her-Face-BBC-Radio-4-Full-cast-Dramatisation-by-P-D-James.pdf
    • http://muicuiu.dumb1.com/4a05a01a00a08a06/The-Good-and-Beautiful-Community-Following-the-Spirit-Extending-Grace-Demonstrating-Love-by-James-Bryan-Smith.pdf
    • http://muicuiu.dumb1.com/3a05a00a07a08a04/New-X-Men-Academy-X-Haunted-by-Nunzio-DeFilippis.pdf
    • http://muicuiu.dumb1.com/7a04a05a06a08a04/City-Walls-The-Urban-Enceinte-in-Global-Perspective-by-James-D-Tracy.pdf
    • http://muicuiu.dumb1.com/1a03a02a05a03a08/Climate-Cover-Up-The-Crusade-to-Deny-Global-Warming-by-James-Hoggan.pdf
    • http://muicuiu.dumb1.com/3a00a08a01a02a08/Batman-Confidential-Vol-6-King-Tut-s-Tomb-by-Nunzio-DeFilippis.pdf
    • http://muicuiu.dumb1.com/8a04a01a08a05a03/Alibaba-