Malicious PDF — malware analysis report

Static analysis result for SHA-256 a61897a8417c5eee…

MALICIOUS

PDF

16.1 KB Created: 2019-05-05 16:14:15 +01:00 Authoring application: mPDF 5.7
MD5: ce96cb052546b163de49e9103f9ac336 SHA-1: 9900b8df5e05161b27870519a58f83916a1f5843 SHA-256: a61897a8417c5eee02589a38ab1ced5af8416b23a1d328508e13cd14bde48eb2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded external links, identified as a link farm. While the URLs themselves appear to point to benign book titles, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a05a03a03a07a03/Parchment-and-Old-Lace-Scrapbooking-Mystery-13-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/4a08a09a02a03a01/Motif-for-Murder-A-Scrapbooking-Mystery-4-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/2a02a08a05a05a05/Oolong-Dead-A-Tea-Shop-Mystery-10-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/2a08a01a02a03a09/Steeped-in-Evil-A-Tea-Shop-Mystery-15-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/2a06a01a05a02a09/Death-by-Darjeeling-A-Tea-Shop-Mystery-1-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/1a06a08a09a05a02/Chamomile-Mourning-A-Tea-Shop-Mystery-6-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/1a06a05a07a01a07/Blood-Orange-Brewing-A-Tea-Shop-Mystery-7-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/1a06a05a05a04a07/Shades-of-Earl-Grey-A-Tea-Shop-Mystery-3-by-Laura-Childs.pdf
    • http://muicuiu.dumb1.com/5a00a02a06a02/The-Parchment-Tale-Unfolds-The-Parchment-Series-2-by-SKETA.pdf
    • http://muicuiu.dumb1.com/5a04a00a08a06/The-Parchment-The-Parchment-Series-1-by-SKETA.pdf
    • http://muicuiu.dumb1.com/1a07a08a02a07a03/Larceny-And-Lace-A-Vintage-Magic-Mystery-2-by-Annette-Blair.pdf
    • http://muicuiu.dumb1.com/4a01a01a06a09a07/Spurs-and-Lace-Lonely-Lace-Series-1-by-Bonnie-R-Paulson.pdf
    • http://muicuiu.dumb1.com/1a07a01a05a05a01/Steel-and-Lace-Lace-1-by-Adriane-Leigh.pdf
    • http://muicuiu.dumb1.com/1a07a01a04a07a04/Whiskey-and-Lace-Lace-2-by-Adriane-Leigh.pdf
    • http://muicuiu.dumb1.com/2a02a09a04a02a07/London-Lace-Complete-Series-London-Lace-1-5-by-Catou-Martine.pdf
    • http://muicuiu.dumb1.com/3a05a06a07a02a08/A-Page-Out-of-Life-A-Scrapbooking-Novel-by-Kathleen-Reid.pdf
    • http://muicuiu.dumb1.com/6a07a03a09a09/Die-Buying-A-Mall-Cop-Mystery-1-by-Laura-DiSilverio.pdf
    • http://muicuiu.dumb1.com/9a05a07a03a00a06/Spooky-Vintage-Pictures-to-Use-in-Your-Scrapbooking-and-Decoupage-Projects-by-Virinia-Downham.pdf
    • http://muicuiu.dumb1.com/7a01a04a09a04a02/Hayburner-A-Gail-McCarthy-Mystery-by-Laura-Crum.pdf
    • http://muicuiu.dumb1.com/2a06a07a04a03a09/The-Big-Brush-off-A-Jake-amp-Laura-Mystery-4-by-Michael-Murphy.pdf
    • http://muicuiu.dumb1.com/4a01a01a06a09a07/Spurs-and-Lace-Lonely-