Malicious PDF — malware analysis report

Static analysis result for SHA-256 a41be4c8ce0a4104…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 05:13:57 +01:00 Authoring application: mPDF 5.7
MD5: 605d26cad274f204d7b4345a2c1a6556 SHA-1: 11de3e1d7fac80e85dc726c295e1166e43668b68 SHA-256: a41be4c8ce0a4104f18f82729ec7dbca3c370aafeea558683987072ab9cb91ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a08a03a02a09a01/Welcome-to-Nowhere-by-Elizabeth-Laird.pdf
    • http://muicuiu.dumb1.com/2a02a03a00a06a06/Red-Sky-in-the-Morning-by-Elizabeth-Laird.pdf
    • http://muicuiu.dumb1.com/1a00a07a00a06a08/Jake-s-Tower-by-Elizabeth-Laird.pdf
    • http://muicuiu.dumb1.com/4a00a08a01a07a03/The-Lure-of-the-Honeybird-The-Storytellers-of-Ethiopia-by-Elizabeth-Laird.pdf
    • http://muicuiu.dumb1.com/3a00a00a03a08a02/A-Laird-to-Hold-A-Laird-for-All-Time-5-by-Angeline-Fortin.pdf
    • http://muicuiu.dumb1.com/1a05a06a00a06/Seduction-and-Betrayal-Women-and-Literature-by-Elizabeth-Hardwick.pdf
    • http://muicuiu.dumb1.com/3a00a09a04a05a07/Echoes-of-Betrayal-Paladin-s-Legacy-3-by-Elizabeth-Moon.pdf
    • http://muicuiu.dumb1.com/4a07a09a07a01a00/Elizabeth-s-Education-The-Inheritance-by-Maggie-Carpenter.pdf
    • http://muicuiu.dumb1.com/5a09a01a06a05a08/The-Blair-Witch-Project-Il-mistero-della-strega-di-Blair-Il-dossier-by-D-A-Stern.pdf
    • http://muicuiu.dumb1.com/4a03a06a06a01a01/Wounds-of-the-Father-A-True-Story-of-Child-Abuse-Betrayal-and-Redemption-by-Elizabeth-Garrison.pdf
    • http://muicuiu.dumb1.com/2a06a02a09a01a05/Betrayal-of-Justice-Zachary-Blake-Betrayal-2-by-Mark-M-Bello.pdf
    • http://muicuiu.dumb1.com/2a05a05a03a07a08/Betrayal-Kyle-s-Revenge-Betrayal-3-by-Sofia-Velardi.pdf
    • http://muicuiu.dumb1.com/2a05a05a09a01a09/Betrayal-Abby-s-Guilt-Betrayal-1-by-Sofia-Velardi.pdf
    • http://muicuiu.dumb1.com/2a01a09a00a09a06/Maggie-Reloaded-Maggie-MacKay-Magical-Tracker-7-by-Kate-Danley.pdf
    • http://muicuiu.dumb1.com/2a07a04a05a02a07/Maggie-s-Image-Maggie-McGill-Mystery-1-by-Sharon-Burch-Toner.pdf
    • http://muicuiu.dumb1.com/2a01a09a00a08a00/Maggie-Get-Your-Gun-Maggie-MacKay-Magical-Tracker-2-by-Kate-Danley.pdf
    • http://muicuiu.dumb1.com/3a00a01a03a07a04/Maggie-at-Sea-Maggie-McGill-Mystery-5-by-Sharon-Burch-Toner.pdf
    • http://muicuiu.dumb1.com/2a00a06a05a04a02/You-re-Mine-Maggie-The-Misadventures-of-Maggie-Mae-2-by-Beth-Yarnall.pdf
    • http://muicuiu.dumb1.com/2a09a05a03a09a08/Tip-It-The-World-According-to-Maggie-by-Maggie-Griffin.pdf
    • http://muicuiu.dumb1.com/8a04a04a00a06a02/Audition-for-Murder-Maggie-Ryan-1967-Maggie-Ryan-and-Nick-O-Connor-1-by-P-M-Carlson.pdf