Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa30099905ce714f…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 04:57:59 +01:00 Authoring application: mPDF 5.7
MD5: b39900668590725cfd1ea5656e717bd0 SHA-1: 3806acd36e179b57450cfc9b3150abaa0d23576c SHA-256: aa30099905ce714f941a8501dabfffd136fa292dd97f6f613f523d799976049f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a multitude of external resources. While the specific intent of these external links is unclear, the sheer volume and the ML classifier's high confidence score point towards a malicious distribution or redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a03a05a04a07/Marriage-The-Unbroken-Marriage---10-Ways-to-Grow-Together-As-A-Couple-And-Save-Your-Marriage-Marriage-Of-Convenience-Marriage-Matters-Marriage-Help-Marriage-Bargain-Marriage-Help-Books-by-Sarah-Riedel.pdf
    • http://muicuiu.dumb1.com/4a08a02a07a03a03/Faery-Magic-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/4a04a04a06a05a03/The-Bargain-Regency-1-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a09a01a00a09a03/The-Rake-Davenport-2-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a09a01a03a08a02/Mischief-and-Mistletoe-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/3a07a03a04a01a08/Mischief-and-Mistletoe-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a04a06a02a01a05/Bride-by-Arrangement-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a08a01a08a01a04/Not-Quite-a-Wife-Lost-Lords-6-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/3a06a04a03a07a03/Never-Less-Than-a-Lady-Lost-Lords-2-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a00a04a02a03a04/Once-a-Rebel-Rogues-Redeemed-2-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a04a09a09a03a09/The-Last-Chance-Christmas-Ball-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/3a04a09a00a03a04/Once-a-Soldier-Rogues-Redeemed-1-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/1a01a01a09a06/Dancing-on-the-Wind-Fallen-Angels-2-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/1a03a00a01a09/Angel-Rogue-Fallen-Angels-4-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/1a03a04a06a07a03/No-Longer-a-Gentleman-Lost-Lords-4-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/3a09a09a06a03a04/Petals-in-the-Storm-Fallen-Angels-3-Regency-2-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a08a05a02a08a05/Loving-a-Lost-Lord-Lost-Lords-1-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/1a09a07a03a07a07/Silk-and-Shadows-Silk-Trilogy-1-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/2a06a05a09a04a04/The-Marriage-of-Mary-Russell-Mary-Russell-and-Sherlock-Holmes-13-5-by-Laurie-R-King.pdf
    • http://muicuiu.dumb1.com/1a05a00a08a01a04/Clementine-Churchill-The-Biography-of-a-Marriage-by-Mary-Soames.pdf