Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad81a1f719247692…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 00:48:58 +01:00 Authoring application: mPDF 5.7
MD5: c18b412a30ebc45901fe97ed257fe5c0 SHA-1: 2b9dadf09ba8974410f9368158ba710f6cc3225f SHA-256: ad81a1f7192476922af1c8746afb4b64876854b02421f878da395e6bb1de6faa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the primary attack pattern involves directing users to a multitude of external sites, likely for SEO poisoning or to serve further malicious content. The URLs themselves are marked as benign, but their sheer volume and the heuristic firing suggest a malicious intent behind their distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a04a02a02a09a09/Dolphin-Boy-Dolphin-Trilogy-1-by-Roy-Meyers.pdf
    • http://muicuiu.dumb1.com/1a01a06a01a09a07a04/Darjeeling-by-T-A-Noonan.pdf
    • http://muicuiu.dumb1.com/7a01a08a09a08a03/Scotch-Ale-by-Greg-Noonan.pdf
    • http://muicuiu.dumb1.com/1a00a06a04a08a01/Dark-Enough-to-See-the-Stars-by-Cindy-Noonan.pdf
    • http://muicuiu.dumb1.com/7a02a04a04a08a01/Chantyal-Dictionary-and-Texts-by-Michael-P-Noonan.pdf
    • http://muicuiu.dumb1.com/4a02a03a02a06a09/What-I-Saw-at-the-Revolution-A-Political-Life-in-the-Reagan-Era-by-Peggy-Noonan.pdf
    • http://muicuiu.dumb1.com/2a07a01a07a02a04/The-Companion-Guide-to-Beautiful-Girlhood-by-Shelly-Noonan.pdf
    • http://muicuiu.dumb1.com/7a05a07a03a01a07/Where-the-Lost-Girls-Go-A-Laura-Mori-Mystery-1-by-R-J-Noonan.pdf
    • http://muicuiu.dumb1.com/3a09a01a09a07a00/With-Love-from-Diana-the-Princess-of-Wales-Personal-Astrologer-Shares-Her-First-Hand-Account-of-Diana-s-Turbulent-Years-by-Penny-Thornton.pdf
    • http://muicuiu.dumb1.com/1a07a06a04a01a08/I-Don-t-Care-If-My-Best-Friend-s-Mom-is-a-Sasquatch-She-s-Hot-and-I-m-Taking-a-Shower-With-Her-by-Lacey-Noonan.pdf
    • http://muicuiu.dumb1.com/7a06a06a08a07/Secrets-The-Third-Story-in-the-Orphan-Train-Trilogy-by-Robert-Noonan.pdf
    • http://muicuiu.dumb1.com/6a06a06a02a03a06/The-Dolphin-Within-by-Olivia-De-Bergerac.pdf
    • http://muicuiu.dumb1.com/4a02a02a03a05a03/Heart-of-a-Dolphin-by-Catherine-Hapka.pdf
    • http://muicuiu.dumb1.com/3a07a09a03a03a02/The-Brass-Dolphin-by-Caroline-Harvey.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a01a09/Dolphin-Girl-by-Shel-Delisle.pdf
    • http://muicuiu.dumb1.com/9a07a08a05a04/Dolphin-Island-by-Arthur-C-Clarke.pdf
    • http://muicuiu.dumb1.com/1a02a05a07a04a08/The-Dolphin-Princess-by-Sylva-Kelegian.pdf
    • http://muicuiu.dumb1.com/6a07a05a07a05/Dolphin-Tale-The-Junior-Novel-by-Gabrielle-Reyes.pdf
    • http://muicuiu.dumb1.com/3a06a04a05a04a07/Dolphin-In-The-Deep-Animal-Ark-31-by-Lucy-Daniels.pdf
    • http://muicuiu.dumb1.com/2a04a05a02a00a09/The-Secret-of-the-Silver-Dolphin-by-Carolyn-Keene.pdf