Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad3aa89dad8156e5…

MALICIOUS

PDF

15.3 KB Created: 2019-05-02 01:20:30 +01:00 Authoring application: mPDF 5.7
MD5: 243841ae60c254d41552a7ced2ffe441 SHA-1: ec4397884b907522163ab68746c26c9b22c35323 SHA-256: ad3aa89dad8156e5959f9653f6651391fdab36e16c0c8a36af95e76d4060deee
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are currently classified as benign, the sheer volume and the nature of the heuristic suggest a link farm intended to manipulate search engine results or redirect users to potentially malicious content. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a00a08a05a07/Beauty-from-Surrender-Beauty-2-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/9a06a01a00a00a06/The-Beauty-Series-Bundle-Beauty-1-3-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/3a04a00a05a09a02/Beauty-From-Pain-Beauty-1-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/1a01a05a02a03a08a04/Felicit-perduta-Beauty-3-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/7a09a07a03a05a09/Universal-Beauty-The-Miss-Universe-Guide-to-Beauty-by-Cara-Birnbaum.pdf
    • http://muicuiu.dumb1.com/1a04a01a09a09/Beauty-A-Retelling-of-the-Story-of-Beauty-and-the-Beast-by-Robin-McKinley.pdf
    • http://muicuiu.dumb1.com/2a00a04a09a04a07/Truly-We-Both-Loved-Beauty-Dearly-The-Story-of-Sleeping-Beauty-as-Told-by-the-Good-and-Bad-Fairies-by-Trisha-Speed-Shaskan.pdf
    • http://muicuiu.dumb1.com/6a04a05a04a06a05/Stealing-Beauty-Possessing-Beauty-2-by-Madison-Faye.pdf
    • http://muicuiu.dumb1.com/3a00a02a00a06a01/Beauty-Touched-the-Beast-Beauty-1-by-Skye-Warren.pdf
    • http://muicuiu.dumb1.com/2a00a00a07a01a02/The-Beauty-Series-Beauty-1-4-by-Skye-Warren.pdf
    • http://muicuiu.dumb1.com/3a09a08a03a02a05/Beneath-the-Beauty-Beauty-2-by-Skye-Warren.pdf
    • http://muicuiu.dumb1.com/4a08a07a04a06/Beauty-s-Release-Sleeping-Beauty-3-by-A-N-Roquelaure.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a01a02/Beauty-Beauty-by-Rebecca-Perry.pdf
    • http://muicuiu.dumb1.com/4a05a03a04a08a02/Broken-Beauty-Broken-Beauty-Novellas-1-by-Chloe-Adams.pdf
    • http://muicuiu.dumb1.com/2a04a05a08a03a09/Cruel-Beauty-Cruel-Beauty-Universe-1-by-Rosamund-Hodge.pdf
    • http://muicuiu.dumb1.com/1a00a07a00a07a06a05/Beauty-amp-the-Beast-Vendetta-Beauty-amp-the-Beast-1-by-Nancy-Holder.pdf
    • http://muicuiu.dumb1.com/2a08a00a07a08a01/Cruel-Beauty-Cruel-Beauty-Universe-1-by-Rosamund-Hodge.pdf
    • http://muicuiu.dumb1.com/2a02a06a05a04a06/A-Necessary-Sin-The-Sin-Trilogy-1-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/1a05a06a06/Indulge-by-Georgia-Cates.pdf
    • http://muicuiu.dumb1.com/3a09a04/The-Next-Sin-The-Sin-Trilogy-2-by-Georgia-Cates.pdf