Malicious PDF — malware analysis report

Static analysis result for SHA-256 accf1c64bf446d3a…

MALICIOUS

PDF

20.3 KB Created: 2019-04-30 04:01:50 +01:00 Authoring application: mPDF 5.7
MD5: 52ad6bc3c78d1fc84f73de1a22be0e15 SHA-1: 882168ed0f778fd1a35f2f732a8ad14683d1204e SHA-256: accf1c64bf446d3a85acc09f0ff25245806d2e58b1ae7ce2d81f2d5310b40e59
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, indicating a potential SEO poisoning or link farm attack. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users or manipulate search results. No scripts were extracted from this sample, limiting further analysis of its behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9809

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a02a03a03a08a02/Black-Shoe-Carrier-Admiral-Frank-Jack-Fletcher-at-Coral-Sea-Midway-and-Guadalcanal-by-John-B-Lundstrom.pdf
    • http://muicuiu.dumb1.com/1a01a02a03a03a08a01/The-First-Team-and-the-Guadalcanal-Campaign-Naval-Fighter-Combat-from-August-to-November-1942-by-John-B-Lundstrom.pdf
    • http://muicuiu.dumb1.com/1a01a02a03a03a07a06/The-First-Team-Pacific-Naval-Air-Combat-from-Pearl-Harbor-to-Midway-by-John-B-Lundstrom.pdf
    • http://muicuiu.dumb1.com/4a01a00a01a09a08/Dauntless-Novel-of-Midway-and-Guadalcanal-by-Barrett-Tillman.pdf
    • http://muicuiu.dumb1.com/8a07a03a02a06a04/The-Coral-Sea-1942-The-first-carrier-battle-by-Mark-Stille.pdf
    • http://muicuiu.dumb1.com/6a07a05a00a07a05/Carrier-Glorious-The-Life-And-Death-Of-An-Aircraft-Carrier-by-John-Winton.pdf
    • http://muicuiu.dumb1.com/1a04a03a05a04a00/Black-Whiteness-Admiral-Byrd-Alone-in-the-Antarctic-by-Robert-Burleigh.pdf
    • http://muicuiu.dumb1.com/6a07a05a00a01a05/Carrier-Life-Aboard-a-World-War-II-Aircraft-Carrier-by-Max-Miller.pdf
    • http://muicuiu.dumb1.com/3a02a08a07a03a01/To-The-Coral-Strand-by-John-Masters.pdf
    • http://muicuiu.dumb1.com/6a07a04a08a05a01/The-Carrier-The-Carrier-Series-Volume-1-by-Diana-Ryan.pdf
    • http://muicuiu.dumb1.com/4a05a00a09a02/Carrier-of-the-Mark-Carrier-1-by-Leigh-Fallon.pdf
    • http://muicuiu.dumb1.com/5a08a07a06a02a03/Black-Jack-A-Jack-Sabre-Thriller-by-Terry-Wright.pdf
    • http://muicuiu.dumb1.com/1a01a02a03a04a03a09/The-First-South-Pacific-Campaign-Pacific-Fleet-Strategy-December-1941-June-1942-by-John-B-Lundstrom.pdf
    • http://muicuiu.dumb1.com/6a07a05a00a07a01/The-Secret-Science-of-Black-Male-and-Female-Sex-The-Secret-Science-of-Sex-Where-the-Physical-Body-Transcends-Into-the-Spiritual-Dimension-by-T-C-Carrier.pdf
    • http://muicuiu.dumb1.com/2a06a07a07a03a06/Jack-Stenhouse-Mysteries-by-Frank-A-Ruffolo.pdf
    • http://muicuiu.dumb1.com/1a01a04a00a02a06a04/Treibt-sie-nach-Norden-Aus-dem-Leben-des-Baylis-John-Fletcher-by-Mark-L-Wood.pdf
    • http://muicuiu.dumb1.com/3a00a06a02a05a01/The-Glass-Admiral-The-Glass-Admiral-1-by-Kit-Smart.pdf
    • http://muicuiu.dumb1.com/1a05a06a04a06a08/Black-Numbers-by-Dean-Frank-Lappi.pdf
    • http://muicuiu.dumb1.com/3a07a00a05a01a02/Black-Numbers-by-Dean-Frank-Lappi.pdf
    • http://muicuiu.dumb1.com/4a01a05a03a02a02/Yellow-Race-in-America-Beyond-Black-and-White-by-Frank-H-Wu.pdf