Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa43eaf615956aef…

MALICIOUS

PDF

18.8 KB Created: 2019-05-02 01:37:18 +01:00 Authoring application: mPDF 5.7
MD5: e4396c39bb85cb03fe90b8809ef76a20 SHA-1: d2ad0969e76b7ee37c5ab44e127f8ac3645aef06 SHA-256: aa43eaf615956aefaf2a8d8cae70c2f57cec28805f35c7da7f8511e71ca5a35e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most individual URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.d
    • http://muicuiu.dumb1.com/7a05a04a06a00a02/Black-Light-by-Martha-J-Allard.pdf
    • http://muicuiu.dumb1.com/3a01a01a01a03a03/Mexican-Light-Exciting-Healthy-Recipes-from-the-Border-and-Beyond-by-Martha-Rose-Shulman.pdf
    • http://muicuiu.dumb1.com/7a05a04a06a00a05/The-Memoirs-Of-General-Jean-V-Allard-by-Jean-V-Allard.pdf
    • http://muicuiu.dumb1.com/7a05a04a05a01a06/The-Photographic-Essay-William-Albert-Allard-by-William-Albert-Allard.pdf
    • http://muicuiu.dumb1.com/7a05a04a05a01a07/William-Albert-Allard-Five-Decades-A-Retrospective-by-William-Albert-Allard.pdf
    • http://muicuiu.dumb1.com/4a03a09a02a04a02/Tommy-Black-and-the-Staff-of-Light-Tommy-Black-1-by-Jake-Kerr.pdf
    • http://muicuiu.dumb1.com/7a00a04a04a04a09/Martha-Inc-The-Incredible-Story-of-Martha-Stewart-Living-Omnimedia-by-Christopher-M-Byron.pdf
    • http://muicuiu.dumb1.com/7a00a04a04a04a04/Martha-The-Life-and-Work-of-Martha-Graham-by-Agnes-De-Mille.pdf
    • http://muicuiu.dumb1.com/7a00a04a04a05a00/Martha-Speaks-Martha-on-the-Case-by-Jamie-White.pdf
    • http://muicuiu.dumb1.com/2a04a05a09a08a00/Black-Light-Bob-Lee-Swagger-2-by-Stephen-Hunter.pdf
    • http://muicuiu.dumb1.com/3a06a03a00a04a06/Suspicion-Black-Light-8-by-Measha-Stone.pdf
    • http://muicuiu.dumb1.com/1a02a01a04a05a05/Deus-Ex-Black-Light-by-James-Swallow.pdf
    • http://muicuiu.dumb1.com/2a03a03a08a01a04/Light-of-the-Last-Wars-of-the-Realm-3-by-Chuck-Black.pdf
    • http://muicuiu.dumb1.com/2a09a09a00a02a02/Roulette-Redux-Black-Light-7-by-Livia-Grant.pdf
    • http://muicuiu.dumb1.com/4a08a03a00a01a01/Eraden-Tales-and-the-Sword-of-Black-Light-2---Veroz-s-Corruption-by-Kristin-Vincent.pdf
    • http://muicuiu.dumb1.com/2a02a08a03a05a08/Martha-Stewart-s-Encyclopedia-of-Crafts-An-A-to-Z-Guide-with-Detailed-Instructions-and-Endless-Inspiration-by-Martha-Stewart.pdf
    • http://muicuiu.dumb1.com/3a01a01a04a09a03/500-Treasured-Country-Recipes-from-Martha-Storey-and-Friends-Mouthwatering-Time-Honored-Tried-And-True-Handed-Down-Soul-Satisfying-Dishes-by-Martha-Storey.pdf
    • http://muicuiu.dumb1.com/7a05a04a06a05a01/The-Mad-Chopper-by-Kent-Allard.pdf
    • http://muicuiu.dumb1.com/7a05a04a06a09a07/Allard-The-Inside-Story-by-Tom-Lush.pdf
    • http://muicuiu.dumb1.com/7a05a04a05a01a08/Victory-Garden-by-Meredith-Allard.pdf