Malicious PDF — malware analysis report

Static analysis result for SHA-256 a01f315c93a8d476…

MALICIOUS

PDF

27.8 KB Created: 2019-04-30 05:51:50 +01:00 Authoring application: mPDF 5.7
MD5: 3f4a83a61741dff40593e7059db9661e SHA-1: 312cec3c16d5acbec7481c4f13358797f306fb24 SHA-256: a01f315c93a8d4763e734b9579cfae5e93bbfbadcd5b076e783d6c284c86897f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Link

The PDF file was flagged by a critical heuristic for containing a mass external PDF link farm, with 32 links detected. The ML classifier also assigned a high probability of maliciousness. While the document body is heavily corrupted and unreadable, the presence of numerous links, many of which are to book titles, suggests a potential SEO poisoning or traffic-driving scheme. The URLs themselves are currently marked as benign, but the sheer volume and the heuristic firing indicate a malicious intent to direct users to external content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a05a00a07a05a02/Somewhere-in-France-A-Novel-of-the-Great-War-by-Jennifer-Robson.pdf
    • http://muicuiu.dumb1.com/2a05a02a05/Moonlight-over-Paris-The-Great-War-3-by-Jennifer-Robson.pdf
    • http://muicuiu.dumb1.com/3a05a02a00a00a05/The-Gown-A-Novel-of-the-Royal-Wedding-by-Jennifer-Robson.pdf
    • http://muicuiu.dumb1.com/4a00a01a07a09a07/France-and-England-in-North-America-Vol-1-Pioneers-of-France-in-the-New-World-The-Jesuits-in-North-America-in-the-Seventeenth-Century-La-Salle-and-the-Discovery-of-the-Great-West-The-Old-Regime-in-Canada-by-Francis-Parkman.pdf
    • http://muicuiu.dumb1.com/5a01a06a03a01a01/France-and-the-Great-War-by-Leonard-V-Smith.pdf
    • http://muicuiu.dumb1.com/7a09a04a05a06a03/Entree-to-Asia-A-Culinary-Adventure-With-Thomas-Robson-by-Thomas-Robson.pdf
    • http://muicuiu.dumb1.com/6a09a04a08a02a03/Airlines-of-France-Air-France-Openskies-Aigle-Azur-XL-Airways-France-Corsairfly-Regional-Compagnie-Aerienne-Europeenne-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/5a01a06a09a08a06/Rousseau-s-Daughters-Domesticity-Education-and-Autonomy-in-Modern-France-by-Jennifer-J-Popiel.pdf
    • http://muicuiu.dumb1.com/1a04a00a03a02a06/A-Great-Improvisation-Franklin-France-and-the-Birth-of-America-by-Stacy-Schiff.pdf
    • http://muicuiu.dumb1.com/7a09a09a08a07a08/August-1914-France-the-Great-War-and-a-Month-That-Changed-the-World-Forever-by-Bruno-Cabanes.pdf
    • http://muicuiu.dumb1.com/8a03a02a00a06a01/Restoring-Order-The-Ecole-Des-Chartes-and-the-Organization-of-Archives-and-Libraries-in-France-1820-1870-by-Lara-Jennifer-Moore.pdf
    • http://muicuiu.dumb1.com/3a08a04a07a04a08/The-Royal-Newfoundland-Regiment-in-the-Great-War-A-Guide-to-the-Battlefields-and-Memorials-of-France-Belgium-and-Gallipoli-by-Frank-Gogos.pdf
    • http://muicuiu.dumb1.com/8a08a09a08a04a08/Flexible-Working-in-Food-Retailing-A-Comparison-Between-France-Germany-Great-Britain-and-Japan-by-Christophe-Baret.pdf
    • http://muicuiu.dumb1.com/8a00a02a00a07a08/Great-Thoroughbred-Sires-of-the-World-by-Jennifer-Churchill.pdf
    • http://muicuiu.dumb1.com/9a07a03a05a08a03/Star-Sisters-and-the-Great-Skate-by-Jennifer-Blecher.pdf
    • http://muicuiu.dumb1.com/8a02a04a09a00a04/The-Cooking-of-Southwest-France-Recipes-from-France-s-Magnificient-Rustic-Cuisine-by-Paula-Wolfert.pdf
    • http://muicuiu.dumb1.com/5a03a09a05a07a02/A-lot-of-tents-in-France-A-tent-in-France-Book-2-by-Simon-Swinn.pdf
    • http://muicuiu.dumb1.com/1a01a09a03a04a05a01/Quinze-ans-de-politiques-d-innovation-en-France-by-France-Strat-gie.pdf
    • http://muicuiu.dumb1.com/8a02a01a02a08/Doubt-A-History-The-Great-Doubters-and-Their-Legacy-of-Innovation-from-Socrates-and-Jesus-to-Thomas-Jefferson-and-Emily-Dickinson-by-Jennifer-Michael-Hecht.pdf
    • http://muicuiu.dumb1.com/7a04a09a08a06a09/Histoire-De-France-En-Bandes-Dessin-es-No-4---Hughes-Capet-Guillame-le-Conqu-rant-Histoire-De-France-4-by-V-ctor-Mora.pdf
    • http://muicuiu.dumb1.com/6a09a04a08a02a03/Airlines