Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3c0eadd982fe956…

MALICIOUS

PDF

23.9 KB Created: 2019-05-02 10:34:39 +01:00 Authoring application: mPDF 5.7
MD5: c50e1b4915d55c072113c4d448e7bf53 SHA-1: d4ee0015ad417cf8930329eaedc43eb6fdf192eb SHA-256: a3c0eadd982fe95638fb8bfaa518a5a43f88fd8383ec233803c66b4ea19e2521
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this document as malicious. The primary attack pattern involves directing users to a domain hosting numerous book-related PDFs, likely as a form of SEO abuse or to host malicious content disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a06a07a01a07a04/Haunted-Canada-5-Terrifying-True-Stories-by-Joel-A-Sutherland.pdf
    • http://muicuiu.dumb1.com/1a06a07a00a09a09/Haunted-Canada-4-More-True-Tales-of-Terror-by-Joel-A-Sutherland.pdf
    • http://muicuiu.dumb1.com/2a02a08a08a04a04/The-Haunted-Graveyard-and-Other-True-Ghost-Stories-by-Allan-Zullo.pdf
    • http://muicuiu.dumb1.com/3a05a08a05a05a02/100-Totally-True-Ghost-Stories-Haunted-1-2-by-Willow-Cross.pdf
    • http://muicuiu.dumb1.com/9a08a00a00a03a01/I-Believe-In-Ghosts-True-Stories-Of-Some-Haunted-Celebrities-And-Their-Celebrated-Haunts-by-Danton-Walker.pdf
    • http://muicuiu.dumb1.com/7a07a08a07a08a07/Surviving-My-Haunted-Life-True-Life-Stories-of-Ghostly-Hauntings-in-Shreveport-La-by-Linda-Mitchell-Logan.pdf
    • http://muicuiu.dumb1.com/2a05a05a00a00a05/Assassin-a-terrifying-true-story-by-Christopher-Robbins.pdf
    • http://muicuiu.dumb1.com/1a02a05a02a09a01/Never-Tell-A-True-Story-of-Overcoming-a-Terrifying-Childhood-by-Catherine-McCall.pdf
    • http://muicuiu.dumb1.com/3a03a05a04a04a03/The-Butler-Did-It-My-True-and-Terrifying-Encounters-with-a-Serial-Killer-by-Paul-Pender.pdf
    • http://muicuiu.dumb1.com/4a09a08a01a02a02/The-Great-Derangement-A-Terrifying-True-Story-of-War-Politics-and-Religion-by-Matt-Taibbi.pdf
    • http://muicuiu.dumb1.com/2a00a08a08a02a09/The-Ku-im-Case-A-Terrifying-True-Story-of-Child-Abuse-Cults-amp-Cannibalism-by-Ryan-Green.pdf
    • http://muicuiu.dumb1.com/7a05a05a00a06/True-Crime-Stories-10-Heinous-True-Crime-Stories-Of-Sickly-Serial-Killers-Murderers-And-Sociopaths-by-Travis-S-Kennedy.pdf
    • http://muicuiu.dumb1.com/1a06a08a04a01a03/The-Oxford-Book-of-English-Love-Stories-by-John-Sutherland.pdf
    • http://muicuiu.dumb1.com/9a07a07a03a07/Near-Death-Experiences-True-stories-of-Near-Death-Experiences-told-by-real-people-True-stories-of-those-who-went-to-Heaven-by-Tessy-Rawlins.pdf
    • http://muicuiu.dumb1.com/6a00a08a01a06a01/Our-Haunted-Lives-True-Life-Ghost-Encounters-by-Jeff-Belanger.pdf
    • http://muicuiu.dumb1.com/1a00a09a06a03a09/Haunted-Virginia-Legends-Myths-and-True-Tales-by-Pamela-K-Kinney.pdf
    • http://muicuiu.dumb1.com/3a06a07a01a06a05/How-God-Used-A-Thunderstorm-and-Other-Devotional-Stories-by-Joel-R-Beeke.pdf
    • http://muicuiu.dumb1.com/6a09a01a01a02a03/C-r-monial-Du-Premier-Concile-Pl-nier-Du-Canada-Ouvert-Solennellement-a-Qu-bec-Le-19-Septembre-1909-Ceremonial-of-the-First-Plenary-Council-of-Canada-Solemnly-Opened-at-Quebec-September-19th-1909-by-Concile-Plenier-Du-Canada.pdf
    • http://muicuiu.dumb1.com/8a01a02a02a06a00/25-True-Saucy-Stories-by-Macy-True.pdf
    • http://muicuiu.dumb1.com/4a09a08a04a07a08/Stories-From-Uncle-Remus-by-Joel-Chandler-Harris.pdf