Malicious PDF — malware analysis report

Static analysis result for SHA-256 b73656f659c0a0c8…

MALICIOUS

PDF

16.5 KB Created: 2019-05-07 04:50:31 +01:00 Authoring application: mPDF 5.7
MD5: a94bb83850cf3558abe5ef932954a428 SHA-1: 171937ae6d2efb5f91353bc36456162bed7639d2 SHA-256: b73656f659c0a0c8a69ef827021455ca046e1e17a9ae4e6290d3b3d27b70d668
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a07a08a02a07a04/Texas-Rough-Texas-Soul-1-by-Sara-York.pdf
    • http://muicuiu.dumb1.com/2a07a08a02a07a02/Texas-Hard-Texas-Soul-2-by-Sara-York.pdf
    • http://muicuiu.dumb1.com/5a06a04a06a00a04/Texas-Sauvage-by-Sara-York.pdf
    • http://muicuiu.dumb1.com/2a00a00a03a04a08/Heart-of-Texas-Vol-1-Lonesome-Cowboy-Texas-Two-Step-Heart-of-Texas-1-2-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/4a07a08a02a07/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://muicuiu.dumb1.com/2a01a06a02a03a09/Texas-Chase-Texas-Tyler-Family-Saga-2-by-Sandra-Brown.pdf
    • http://muicuiu.dumb1.com/1a01a03a00a07a06a07/Texas-Lucky-Texas-Tyler-Family-Saga-1-by-Sandra-Brown.pdf
    • http://muicuiu.dumb1.com/2a05a05a03a07a04/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://muicuiu.dumb1.com/1a09a02a00a04a06/Texas-Splendor-Leigh-Brothers-Texas-Trilogy-3-by-Lorraine-Heath.pdf
    • http://muicuiu.dumb1.com/4a07a06a04a05a05/A-Match-Made-in-Texas-Deep-in-the-Heart-of-Texas-6-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/1a07a02a03a00a06/Texas-Two-Step-Whispering-Springs-Texas-1-by-Cynthia-D-39-Alba.pdf
    • http://muicuiu.dumb1.com/9a08a02a01a00a09/Flirting-with-Texas-Deep-in-the-Heart-of-Texas-5-by-Katie-Lane.pdf
    • http://muicuiu.dumb1.com/1a07a02a03a09a03/Mistletoe-in-Texas-Texas-Rodeo-5-by-Kari-Lynn-Dell.pdf
    • http://muicuiu.dumb1.com/2a08a01a02a03a07/Texas-Twist-Texas-Montgomery-Mavericks-4-by-Cynthia-D-39-Alba.pdf
    • http://muicuiu.dumb1.com/1a01a04a05a02a04a01/Texas-Free-The-Tylers-of-Texas-5-by-Janet-Dailey.pdf
    • http://muicuiu.dumb1.com/1a04a05a05a07a07/Blame-It-On-Texas-Hotter-In-Texas-2-by-Christie-Craig.pdf
    • http://muicuiu.dumb1.com/8a04a06a04a05/A-Rogue-in-Texas-Rogues-in-Texas-1-by-Lorraine-Heath.pdf
    • http://muicuiu.dumb1.com/5a01a06a05a06a07/Texas-Women-on-the-Cattle-Trails-by-Sara-R-Massey.pdf
    • http://muicuiu.dumb1.com/4a06a01a06a08/Texas-Rich-Texas-1-by-Fern-Michaels.pdf
    • http://muicuiu.dumb1.com/4a02a00a07a07a08/Heart-of-Texas-Volume-3-Nell-s-Cowboy-amp-Lone-Star-Baby-Heart-of-Texas-5-6-by-Debbie-Macomber.pdf
    • http://muicuiu.dumb1.com/4a07a06a04a05a05/