Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5b18e859b934eb4…

MALICIOUS

PDF

28.0 KB Created: 2019-05-03 16:54:14 +01:00 Authoring application: mPDF 5.7
MD5: 3d2f409202d6e2e120884a7b4f56a8bc SHA-1: adb98d244e1bcae22a169d75812cad44a6dd0e60 SHA-256: a5b18e859b934eb49dd05e9d141a7409ab416652cedc099107f7c4d67a72029c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or redirection scheme. The ML classifier also flagged the document as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a04a04a07a02a03/Judisches-Museum-Judisches-Museum-in-Deutschland-Judisches-Museum-Westfalen-Judisches-Museum-Berlin-Schrein-Des-Buches-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a04a04a07a02a04/Judisches-Museum-in-Deutschland-Judisches-Museum-in-Baden-Wurttemberg-Judisches-Museum-in-Bayern-Judisches-Museum-in-Rheinland-Pfalz-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a02a04a03a01a06/How-to-Build-a-Museum-Smithsonian-s-National-Museum-of-African-American-History-and-Culture-by-Tonya-Bolden.pdf
    • http://muicuiu.dumb1.com/1a01a03a09a05a00a01/Kleines-j-disches-Kochbuch-Mit-j-dischen-Anekdoten-by-Eva-Saunders.pdf
    • http://muicuiu.dumb1.com/7a05a06a04a09a09/Museum-of-Fine-Arts-Boston-Paintings-of-the-Museum-of-Fine-Arts-Boston-Ananda-Coomaraswamy-the-Daughters-of-Edward-Darley-Boit-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a07a09a03a03/Museum-of-Flight-100-Years-of-Aviation-History-From-the-Wright-Bros-to-the-Moon-by-Museum-of-Flight.pdf
    • http://muicuiu.dumb1.com/1a01a01a09a08a03a00/Museum-in-Hamburg-Hamburger-Kunsthalle-Miniatur-Wunderland-Liste-Der-Museen-in-Hamburg-Freilichtmuseum-Am-Kiekeberg-Ballinstadt-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a01a00a08a02a04/Kultur-Potsdam-Filmwirtschaft-Potsdam-Museum-in-Potsdam-Sanssouci-Ufa-Defa-Stadtschloss-Villa-Schoningen-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a07a07a06/Hamburg-Bahnhof-Museum-for-the-Present-Berlin-by-Penelope-Crowe.pdf
    • http://muicuiu.dumb1.com/9a05a06a02a08a01/Special-Catalogue-of-the-Royal-Museums-at-Berlin-A-the-Old-Museum-by-Wassermann.pdf
    • http://muicuiu.dumb1.com/1a01a03a00a07a09a05/Kultur-Chemnitz-Kunstler-Chemnitz-Medien-Chemnitz-Museum-in-Chemnitz-Karl-Schmidt-Rottluff-Stefan-Heym-Michael-Degen-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a05a01a08a08a02/Kultur-Zurich-Film-Zurich-Kunst-Zurich-Literatur-Zurich-Museum-in-Zurich-Musik-Zurich-Theater-in-Zurich-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a01a05a05a07a00a01/Museum-in-Noord-Holland-Luchthaven-Schiphol-Zaanse-Schans-Museumstoomtram-Hoorn---Medemblik-Gemaal-de-Cruquius-by-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a08a03a00a03a04/Bildung-in-Aachen-Hochschule-in-Aachen-Museum-in-Aachen-Rwth-Aachen-Schule-in-Aachen-Hauptgebaude-Der-Rwth-Aachen-FH-Aachen-Superc-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a09a05a03a08a04/The-Museum-by-Susan-Verde.pdf
    • http://muicuiu.dumb1.com/1a00a00a07a06a02a07/Birthday-at-the-Museum-by-Brittany-Reiher.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a05a06/The-Barnum-Museum-by-Steven-Millhauser.pdf
    • http://muicuiu.dumb1.com/5a00a09a09a04a05/Stacey-Goes-to-the-National-Museum-by-Lianne-Ong.pdf
    • http://muicuiu.dumb1.com/3a09a08a09a05a02/How-to-Take-Your-Grandmother-to-the-Museum-by-Lois-Wyse.pdf
    • http://muicuiu.dumb1.com/9a09a03a08a01/Behind-the-Scenes-at-the-Museum-by-Kate-Atkinson.pdf