Malicious PDF — malware analysis report

Static analysis result for SHA-256 b08e5e6b7c569f8a…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 09:42:28 +01:00 Authoring application: mPDF 5.7
MD5: 60e6553e2d61dcb8a46ca14c9a72952f SHA-1: 2c88480d787464c88e7482a4adcce2c0896b30df SHA-256: b08e5e6b7c569f8ae4e228c1c027ca9ef4d81c03f1b3200fc9f2b7196339f5a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF documents, characteristic of a link farm. This suggests the document's primary purpose is to redirect users to a malicious website or a collection of potentially harmful content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact nature of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a03a09a05a00a04/Frisch-Three-Plays-Fire-Raisers-Andorra-Triptych-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/3a03a03a02a09a09/A-Foreign-Range-Range-4-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/4a02a02a04a02a02/A-Foreign-Range-Range-4-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/6a09a02a00a00/A-Shared-Range-Range-1-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/3a03a03a02a09a04/An-Isolated-Range-Range-5-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/3a03a03a02a09a07/A-Volatile-Range-Range-6-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/4a05a07a00a02a01/An-Isolated-Range-Range-5-by-Andrew-Grey.pdf
    • http://muicuiu.dumb1.com/8a01a06a04a08a00/Baseball---Major-League-Baseball-Players-from-California-Aaron-Harang-Aaron-Hill-Aaron-Small-Abe-Alvarez-Adam-Kennedy-Adam-Laroche-Alan-Trammell-Ben-Francisco-Bill-Buckner-Billy-Bean-Billy-Rohr-Bob-Boone-Bobby-Bonds-Bobby-Crosby-by-Source-Wikia.pdf
    • http://muicuiu.dumb1.com/8a06a05a03a00a06/Bluebeard-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/1a03a09a07a09a04/Man-in-the-Holocene-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/7a09a00a01a02a07/Hamsters-by-Otto-von-Frisch.pdf
    • http://muicuiu.dumb1.com/3a04a09a06a04/Homo-Faber-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/1a07a06a00a03a07/Man-in-the-Holocene-A-Story-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/8a06a05a02a02a05/The-Missing-Year-by-Belinda-Frisch.pdf
    • http://muicuiu.dumb1.com/7a02a02a09a02a02/Brahms-The-Four-Symphonies-by-Walter-Frisch.pdf
    • http://muicuiu.dumb1.com/7a02a02a09a03a00/Brahms-and-His-World-by-Walter-Frisch.pdf
    • http://muicuiu.dumb1.com/2a09a04a01a00a09/Dead-Spell-by-Belinda-Frisch.pdf
    • http://muicuiu.dumb1.com/3a00a04a08a04a01/Wolverine-by-Jason-Aaron-The-Complete-Collection-Volume-1-by-Jason-Aaron.pdf
    • http://muicuiu.dumb1.com/1a00a05a02a06a07a08/Gesammelte-Werke-in-zeitlicher-Folge-7-Bde-by-Max-Frisch.pdf
    • http://muicuiu.dumb1.com/9a05a05a02a03a03/Maneater-aus-der-Kannibalenk-che-frisch-serviert-by-J-P-Rabo.pdf