Malicious PDF — malware analysis report

Static analysis result for SHA-256 a177e0a5e4a7d93b…

MALICIOUS

PDF

16.0 KB Created: 2019-05-07 06:14:42 +01:00 Authoring application: mPDF 5.7
MD5: e9978a65a4cdf1c898f950b08e1a61a3 SHA-1: 4583787bb15cc9fcdd65e30f114311d291867274 SHA-256: a177e0a5e4a7d93bacefb5389d8f77d10f4bdb3b04d440812e4e06c834ca29e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely SEO poisoning or driving traffic to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a08a09a00a04a08/The-Call-of-the-Deep-The-Matchless-Deep-1-by-Tracy-Lane.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a08a05/The-Call-of-the-Deep-The-Matchless-Deep-1-by-Tracy-Lane.pdf
    • http://muicuiu.dumb1.com/7a05a09a04a09a05/Out-in-the-Deep-Out-in-College-1-by-Lane-Hayes.pdf
    • http://muicuiu.dumb1.com/3a01a06a01a07a00/The-Deep-of-the-Sound-Bluewater-Bay-8-by-Amy-Lane.pdf
    • http://muicuiu.dumb1.com/2a00a04a04a00a09/A-Deep-Dark-Call-by-Rose-Vane.pdf
    • http://muicuiu.dumb1.com/3a07a04a07a04a03/Fathom-Volume-2-Into-The-Deep-by-Michael-Lane-Turner.pdf
    • http://muicuiu.dumb1.com/2a08a05a05a01a08/Make-Mine-a-Bad-Boy-Deep-in-the-Heart-of-Texas-2-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/1a07a09a05a00a01/Catch-Me-A-Cowboy-Deep-in-the-Heart-of-Texas-3-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/1a08a05a03a02a03/Deep-Deep-Sea-by-Frann-Preston-Gannon.pdf
    • http://muicuiu.dumb1.com/9a06a05a09a03a03/Deep-Drilling-in-Crystalline-Bedrock-Volume-2-Review-of-Deep-Drilling-Projects-Technology-Sciences-and-Prospects-for-the-Future-by-A-Boden.pdf
    • http://muicuiu.dumb1.com/1a03a03a07a01/Way-Down-Deep-Way-Down-Deep-1-by-Ruth-White.pdf
    • http://muicuiu.dumb1.com/4a04a05a03a02a06/In-Too-Deep-In-Too-Deep-1-by-Eliza-Jane.pdf
    • http://muicuiu.dumb1.com/4a03a01a04a01/Into-the-Deep-Into-the-Deep-1-by-Samantha-Young.pdf
    • http://muicuiu.dumb1.com/7a02a00a05a00/Emily-of-Deep-Valley-Deep-Valley-2-by-Maud-Hart-Lovelace.pdf
    • http://muicuiu.dumb1.com/4a07a06a04a05a05/A-Match-Made-in-Texas-Deep-in-the-Heart-of-Texas-6-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/9a08a02a01a00a09/Flirting-with-Texas-Deep-in-the-Heart-of-Texas-5-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/1a09a05a01a01a01/Water-So-Deep-Water-So-Deep-1-by-Nichole-Giles.pdf
    • http://muicuiu.dumb1.com/2a05a03a06a05a09/Deep-Black-Deep-Black-1-by-Stephen-Coonts.pdf
    • http://muicuiu.dumb1.com/9a00a05a06a09/Skin-Deep-Skin-Deep-1-by-J-M-Stone.pdf
    • http://muicuiu.dumb1.com/3a02a08a07a09a08/Going-Deep-by-G-A-Hauser.pdf
    • http://muicuiu.dumb1.com/9a06a05a09a03a03/Deep-Drilling-in-Crystalline-Bedrock-Volume-2-Review-of-Deep-Drilling-Projects-Technology-Sciences-and-Prospects-for-the-Future-by-A-Boden