Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2d19ce1759745fd…

MALICIOUS

PDF

16.1 KB Created: 2019-05-07 08:30:54 +01:00 Authoring application: mPDF 5.7
MD5: 6688f2447fcff7b4c64825539dbc6337 SHA-1: f19e356d40a0d83e28f34dd2382588edc6501c6e SHA-256: a2d19ce1759745fdcd405d422dbb2f464d3a737cce3d0fd7eb1b3fe503950036
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to redirect users to malicious content. The ML classifier strongly supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a06a06a03a05a04/Inflame-Me-Ravage-MC-4-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/4a05a06a01a00a03/Satisfy-Me-Ravage-MC-3-5-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/4a08a00a02a00a04/Connected-in-Pain-Ravage-MC-Rebellion-1-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/7a05a02a03a05a05/Fueled-in-Fire-Ravage-MC-Rebellion-2-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/3a05a04a00a06a00/Bound-by-Wreckage-Ravage-MC-Bound-6-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/7a05a02a03a00a07/Bound-by-Vengeance-Ravage-MC-Bound-3-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/4a01a00a07a03a00/Bound-by-Destiny-Ravage-MC-Bound-5-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/3a09a08a09a07a09/Bound-by-Desire-Ravage-MC-Bound-2-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/1a08a04a05a08a04/The-Alpha-s-Bargain-by-Ryan-Michele.pdf
    • http://muicuiu.dumb1.com/5a02a09a04a05a03/A-Florentine-Death-Michele-Ferrara-1-by-Michele-Giuttari.pdf
    • http://muicuiu.dumb1.com/6a01a05a03a04/A-Death-In-Tuscany-Michele-Ferrara-2-by-Michele-Giuttari.pdf
    • http://muicuiu.dumb1.com/3a08a07a07/Ravage-Scarred-Souls-3-by-Tillie-Cole.pdf
    • http://muicuiu.dumb1.com/4a05a06a07a01a05/Ride-with-Me-Hellions-MC-7-5-Ravage-MC-5-5-by-Chelsea-Camaron.pdf
    • http://muicuiu.dumb1.com/4a01a08a02a02a05/Ravage-Civil-Corruption-4-by-Jessica-Prince.pdf
    • http://muicuiu.dumb1.com/7a04a01a08a02a08/Ravage-and-Surrender-The-Billionaire-s-Temptation-5-by-Cali-MacKay.pdf
    • http://muicuiu.dumb1.com/7a05a02a03a06a02/The-G-I-Handbook-How-the-Glycemic-Index-Works-by-Barbara-Ravage.pdf
    • http://muicuiu.dumb1.com/3a02a06a06a00a09/Mud-Stories-of-Sex-and-Love-Michele-Roberts-by-Mich-le-Roberts.pdf
    • http://muicuiu.dumb1.com/2a03a07a01a00a04/Rehearsal-for-Murder-Maggie-Ryan-1973-Maggie-Ryan-and-Nick-O-Connor-5-by-P-M-Carlson.pdf
    • http://muicuiu.dumb1.com/8a04a04a00a06a02/Audition-for-Murder-Maggie-Ryan-1967-Maggie-Ryan-and-Nick-O-Connor-1-by-P-M-Carlson.pdf
    • http://muicuiu.dumb1.com/8a03a08a00a04a04/The-Devaney-Brothers-Ryan-and-Sean-Ryan-s-Place-Sean-s-Reckoning-by-Sherryl-Woods.pdf