Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9d748ff5747b9e5…

MALICIOUS

PDF

17.6 KB Created: 2019-05-07 06:18:59 +01:00 Authoring application: mPDF 5.7
MD5: 84fe0826b865252a3bdd32d99e579028 SHA-1: 133bda6441f6899544d31c0982f1ef56cb8615f6 SHA-256: b9d748ff5747b9e5d898eef5f6a03c452df3943debfec7e0f041e510a349eaba
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier flagged this PDF as malicious with high confidence. The primary attack pattern involves directing users to a domain hosting a link farm, likely as a precursor to a more direct attack or to generate traffic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a09a02a09a04a02/Ranpo-Edogawa-Complete-works-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a02a02a08/--Hitodenashi-No-Koi-Imomushi-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/4a08a05a05a02a09/The-Fiend-with-Twenty-Faces-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a02a02a04/-Kamen-No-Ky-fu-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/2a05a03a07a05a09/Moju-The-Blind-Beast-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a01a06a04/Kaijin-Nijumensou-Boy-Detectives-1-by-Rampo-Edogawa.pdf
    • http://muicuiu.dumb1.com/3a09a04a06a03a08/Poirot-s-Early-Cases-Hercule-Poirot-41-by-Agatha-Christie.pdf
    • http://muicuiu.dumb1.com/5a08a08a08a06a02/Ruth-Galloway-The-Early-Cases-Ruth-Galloway-1-3-by-Elly-Griffiths.pdf
    • http://muicuiu.dumb1.com/2a07a04a07a09a05/Poirot-s-Early-Cases-18-Hercule-Poirot-Mysteries-Hercule-Poirot-41-by-Agatha-Christie.pdf
    • http://muicuiu.dumb1.com/1a00a09a02a09a06a02/Edogawa-shi-to-watashi-by-Fuboku-Kosakai.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a00a05a03/Wacher-in-the-Attic-and-Inju-of-Ranpo-EDOGAWA-by-shogo-kisaragi.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a00a05a04/The-world-of-Ranpo-Edogawa-The-Human-chair-by-shogo-kisaragi.pdf
    • http://muicuiu.dumb1.com/4a04a08a03a09a01/Never-Too-Early-Full-Circle-Never-Too-Early-3-by-Chris-Owen.pdf
    • http://muicuiu.dumb1.com/5a06a00a07a08a01/Early-to-Death-Early-to-Rise-by-Kim-Harrison.pdf
    • http://muicuiu.dumb1.com/2a02a06a03a00a01/Process-is-the-Punishment-The-Handling-Cases-in-a-Lower-Criminal-Court-Handling-Cases-in-a-Lower-Criminal-Court-by-Malcolm-M-Feeley.pdf
    • http://muicuiu.dumb1.com/2a05a04a05a01a06/The-Ultimate-Guide-to-Retirement-Planning-How-To-Retire-Early-And-Stay-Wealthy-For-Ever-Retirement-for-Dummies-Retirement-Investing-Early-Retirement-by-Jacob-Lindgren.pdf
    • http://muicuiu.dumb1.com/1a08a03a04a06a00/Violent-Cases-by-Neil-Gaiman.pdf
    • http://muicuiu.dumb1.com/8a01a08a00a07a07/Torts-Cases-and-Materials-by-Aaron-D-Twerski.pdf
    • http://muicuiu.dumb1.com/1a01a03a00a00a04a06/250-Cases-in-Clinical-Medicine-by-Ragavendra-R-Baliga.pdf
    • http://muicuiu.dumb1.com/6a04a04a05a08/Exotica-The-Nightshade-Cases-2-by-Patti-Larsen.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a00a05a04/The-world-of-Ranpo-Edogaw