Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0442cdf5ae9f9ca…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 04:01:36 +01:00 Authoring application: mPDF 5.7
MD5: 648eef6f94c7f4ea33f562dcd1818276 SHA-1: befbd3f5437f53fa41d4fcdcbe2f38cdd0f197d1 SHA-256: b0442cdf5ae9f9cacca753d694646e1af2e24d1376672118f3efa417aab716b2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS heuristic suggest a malicious intent, likely for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a09a02a04a00a04/The-Stone-Face-by-W-G-Smith.pdf
    • http://muicuiu.dumb1.com/3a07a01a01a04a05/Calm-Face-by-Bud-Smith.pdf
    • http://muicuiu.dumb1.com/2a01a01a01a07a08/Under-Cold-Stone-A-Constable-Molly-Smith-Mystery-Constable-Molly-Smith-Novels-by-Vicki-Delany.pdf
    • http://muicuiu.dumb1.com/3a04a07a09a02a03/Casting-in-Stone-by-Morgan-Smith.pdf
    • http://muicuiu.dumb1.com/4a03a00a06a04/Stone-Quarry-Lydia-Chin-amp-Bill-Smith-6-by-S-J-Rozan.pdf
    • http://muicuiu.dumb1.com/1a00a01a08a09a02/Joseph-Smith-Rough-Stone-Rolling-by-Richard-L-Bushman.pdf
    • http://muicuiu.dumb1.com/9a02a07a06a07a07/Face-To-Face-Encounters-Between-Jews-amp-Blacks-Photographs-And-Text-by-Laurence-Salzmann.pdf
    • http://muicuiu.dumb1.com/7a04a07a04a01a05/Interaction-Ritual---Essays-on-Face-to-Face-Behavior-by-Erving-Goffman.pdf
    • http://muicuiu.dumb1.com/1a01a01a03a03a07a00/Talking-to-Terrorists-Face-to-Face-with-the-Enemy-by-Peter-Taylor.pdf
    • http://muicuiu.dumb1.com/1a01a08a04a07a09a00/The-Nazis---Through-the-Eyes-of-a-Child-The-autobiography-of-a-young-Jewish-refugee-who-came-face-to-face-with-Hitler-by-Margarete-Mendelsohn.pdf
    • http://muicuiu.dumb1.com/1a00a08a00a01a09a00/Lotte-Lasersteing-Face-to-Face-by-Alexander-Eiling.pdf
    • http://muicuiu.dumb1.com/8a05a03a04a01a07/Face-to-Face-With-Elephants-by-Dereck-Joubert.pdf
    • http://muicuiu.dumb1.com/4a09a03a09a00a07/Holiday-in-Stone-Creek-A-Stone-Creek-Christmas-At-Home-in-Stone-Creek-Stone-Creek-4-amp-6-by-Linda-Lael-Miller.pdf
    • http://muicuiu.dumb1.com/4a01a00a00a08a07/Skull-Face-and-Others-Skull-Face-Omnibus-Volume-1-by-Robert-E-Howard.pdf
    • http://muicuiu.dumb1.com/7a04a05a04a00/Guitar-Face-Guitar-Face-1-by-Sasha-Marshall.pdf
    • http://muicuiu.dumb1.com/5a01a01a03a02/Guitar-Face-Guitar-Face-1-by-Sasha-Marshall.pdf
    • http://muicuiu.dumb1.com/7a05a06a00a02a09/Dressed-Stone-Types-of-Stone-Details-Examples-by-Theodor-Hugues.pdf
    • http://muicuiu.dumb1.com/4a08a08a04a06a04/Rebuilding-Stone-The-Stone-Brother-2-by-T-Saint-John.pdf
    • http://muicuiu.dumb1.com/3a00a02a02a06a05/Stone-Rules-The-Stone-Brothers-1-by-Samantha-Christy.pdf
    • http://muicuiu.dumb1.com/1a04a04a07a09a02/Stepping-Stone-The-Stone-Series-2-by-Dakota-Willink.pdf
    • http://muicuiu.dumb1.com/7a