Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2ca5b851507b0d3…

MALICIOUS

PDF

16.6 KB Created: 2019-05-03 06:08:32 +01:00 Authoring application: mPDF 5.7
MD5: 1d7fd11062fcd2563731d426707a3dbc SHA-1: c11d7cb411f257d01d1504ba4b88f7a584d30ab0 SHA-256: b2ca5b851507b0d3ced9d6d23d72c07b56b13efcb8919a836412c861ac69ad00
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a09a02a05a08a07/Funk-Bass-Bass-Builders-Series-by-Jon-Liebman.pdf
    • http://muicuiu.dumb1.com/7a01a08a09a09a04/The-Bass-Clef-Learn-and-Practice-The-Notes-of-The-Bass-Clef-The-Clefs-Volume-2-by-Steve-Tirpak.pdf
    • http://muicuiu.dumb1.com/4a06a03a08a09/Freedom-Over-Me-Eleven-Slaves-Their-Lives-and-Dreams-Brought-to-Life-by-Ashley-Bryan-by-Ashley-Bryan.pdf
    • http://muicuiu.dumb1.com/2a02a05a05a00a08/Bass-Ackwards-and-Belly-Up-Bass-Ackwards-and-Belly-Up-1-by-Elizabeth-Craft.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a08a04/Dark-Passage-Chosen-1-by-M-L-Woolley.pdf
    • http://muicuiu.dumb1.com/8a01a02a00a00a05/Rowen-and-the-King-by-Michael-N-Woolley.pdf
    • http://muicuiu.dumb1.com/2a00a07a01a09a01/Standing-by-the-Watchtower-Volume-1-by-C-S-Woolley.pdf
    • http://muicuiu.dumb1.com/1a02a04a06a05a02/Underworld-Dark-Passage-2-by-M-L-Woolley.pdf
    • http://muicuiu.dumb1.com/9a08a08a05a05/Dying-Notes-by-Reuben-Woolley.pdf
    • http://muicuiu.dumb1.com/2a01a00a03a00a09/Compass-of-God-The-Promised-Land-5-by-David-G-Woolley.pdf
    • http://muicuiu.dumb1.com/1a02a08a05a06a08/Filling-the-Afterlife-from-the-Underworld-Volume-2-by-C-S-Woolley.pdf
    • http://muicuiu.dumb1.com/1a08a09a08a02a06/God-s-Favor---Breath-Of-Heaven-by-Michele-Woolley.pdf
    • http://muicuiu.dumb1.com/4a06a07a03a06a06/Dark-Passage-Chosen-Book-1-by-M-L-Woolley.pdf
    • http://muicuiu.dumb1.com/1a07a02a06a05a01/Rising-Empire-Part-1-The-Chronicles-of-Celadmore-1-by-C-S-Woolley.pdf
    • http://muicuiu.dumb1.com/2a01a00a01a08a07/Pillar-of-Fire-The-Promised-Land-1-by-David-G-Woolley.pdf
    • http://muicuiu.dumb1.com/9a01a05a08a07/Ashley-Bryan-s-ABC-of-African-American-Poetry-by-Ashley-Bryan.pdf
    • http://muicuiu.dumb1.com/1a03a02a00a09a04/The-Derek-Long-Saga-Nicolette-Mace-The-Raven-Siren-3-by-C-S-Woolley.pdf
    • http://muicuiu.dumb1.com/1a01a05a08a09a04a08/Ashley-Bryan-s-African-Tales-Uh-Huh-by-Ashley-Bryan.pdf
    • http://muicuiu.dumb1.com/1a00a00a05a09a01/Seven-Summits-by-Dick-Bass.pdf
    • http://muicuiu.dumb1.com/1a00a06a05a08a00/everything-you-know-by-Mary-Beth-Bass.pdf