Malicious PDF — malware analysis report

Static analysis result for SHA-256 b252591822f3cb5a…

MALICIOUS

PDF

17.7 KB Created: 2019-05-02 01:09:24 +01:00 Authoring application: mPDF 5.7
MD5: 8f055dd2c2d4d5cfa4df46d91682cae5 SHA-1: 885a893c1c0fe577bbdcd166255d1ff80594b89b SHA-256: b252591822f3cb5a8be6e888ea824bbc2ed77c159160ccf7e55acd88cd828f95
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded links to external PDF documents, forming a link farm. This is indicative of SEO poisoning or a similar technique to drive traffic to malicious or low-quality content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.c
    • http://muicuiu.dumb1.com/9a03a05a04a06a02/Hiroshige-A-Shoal-Of-Fishes-by-Hiroshige-Ando-amp-x304-.pdf
    • http://muicuiu.dumb1.com/9a03a05a03a08a07/The-Sketchbooks-of-Hiroshige-by-Hiroshige-Utagawa.pdf
    • http://muicuiu.dumb1.com/9a05a08a01a01a05/Italian-Renaissance-Art-from-Czech-Collections-Drawings-and-Prints-December-12-1996-February-9-1997-Kinsky-Palace-Collection-of-Prints-and-Drawi-by-Martin-Zlatohlavek.pdf
    • http://muicuiu.dumb1.com/1a09a07a09a03a05/A-Summer-of-Faulkner-As-I-Lay-Dying-The-Sound-and-the-Fury-Light-in-August-by-William-Faulkner.pdf
    • http://muicuiu.dumb1.com/5a01a05a06a06a09/Holding-the-Line-How-Britain-s-Railways-Were-Saved-Richard-Faulkner-and-Chris-Austin-by-Richard-Faulkner.pdf
    • http://muicuiu.dumb1.com/3a03a01a08a04a02/The-Portable-Faulkner-by-William-Faulkner.pdf
    • http://muicuiu.dumb1.com/6a09a02a06a02a08/The-William-Faulkner-Audio-Collection-by-William-Faulkner.pdf
    • http://muicuiu.dumb1.com/9a03a05a03a08a08/Hiroshige-by-Christopher-Wynne.pdf
    • http://muicuiu.dumb1.com/9a03a05a03a07a08/Hiroshige-by-Matthi-Forrer.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a07a05/Hiroshige-Famous-Views-by-Narazaki.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a06a06/Hiroshige-Bk-of-Postcards-REV-by-Brooklyn-Museum-of-Art.pdf
    • http://muicuiu.dumb1.com/9a03a05a03a09a03/Hiroshige-One-Hundred-Views-of-Edo-by-Mikhail-Uspensky.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a08a06/Hiroshige-s-View-of-Tokyo-by-Oliver-Impey.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a07a02/Hiroshige-s-Views-of-Mt-Fuji-by-Oliver-Impey.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a07a07/Hiroshige-and-Japanese-Landscapes-by-Yone-D-Noguchi.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a05a09/Rediscovering-the-Old-Tokaido-In-the-Footsteps-of-Hiroshige-by-Patrick-Carey.pdf
    • http://muicuiu.dumb1.com/2a01a07a01a06a00/Finger-Prints-by-Barbara-Delinsky.pdf
    • http://muicuiu.dumb1.com/5a00a02a00a02a07/New-Prints-In-Old-Calico-by-Jennifer-Lynn.pdf
    • http://muicuiu.dumb1.com/7a05a03a01a03a03/Rupert-by-KayeC-Jones.pdf
    • http://muicuiu.dumb1.com/9a05a07a09a03/Before-the-Dawn-by-Rupert-Copping.pdf