Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba6c71d9cbd59ff5…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 04:40:54 +01:00 Authoring application: mPDF 5.7
MD5: 2925d6183691e15326c9b253cf0bdb2b SHA-1: 8afd17cbed2e8042beb4083f36db3d1928a622a6 SHA-256: ba6c71d9cbd59ff5090b7ca5dc2f87fe2569707b74edf8c62b07011fdcefc055
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, identified as a link farm. While the document body itself is not readable, the heuristic firings strongly suggest a malicious intent to redirect users to potentially harmful content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a08a03a06a02a09/Submitting-to-Freedom-The-Religious-Vision-of-William-James-by-Bennett-Ramsey.pdf
    • http://muicuiu.dumb1.com/2a01a07a04a08a08/The-Varieties-of-Religious-Experience-by-William-James.pdf
    • http://muicuiu.dumb1.com/3a07a07a04a02/The-Varieties-of-Religious-Experience-by-William-James.pdf
    • http://muicuiu.dumb1.com/7a03a01a06a01a07/Varieties-of-Religious-Experience-A-Study-of-Human-Nature-Human-Immortality-Two-Supposed-Objections-to-the-Doctrine-by-William-James.pdf
    • http://muicuiu.dumb1.com/1a01a07a00a03a07a07/True-Freedom-On-Protecting-Human-Dignity-and-Religious-Liberty-by-Timothy-M-Dolan.pdf
    • http://muicuiu.dumb1.com/7a01a09a09a02a04/Agents-of-Terror-Queen-Elizabeth-1st-amp-St-Edmund-Campion-Religious-Freedom-or-Government-Control-Which-is-the-terrorist-by-Sarita-Mirador.pdf
    • http://muicuiu.dumb1.com/1a00a06a06a00a03a07/Tea-in-China-A-Religious-and-Cultural-History-by-James-A-Benn.pdf
    • http://muicuiu.dumb1.com/8a06a05a05a04a00/In-the-Valley-of-the-Shadow-On-the-Foundations-of-Religious-Belief-by-James-L-Kugel.pdf
    • http://muicuiu.dumb1.com/4a02a05a02a01a04/The-Myth-of-Religious-Neutrality-An-Essay-on-the-Hidden-Role-of-Religious-Belief-in-Theories-Revised-Edition-by-Roy-A-Clouser.pdf
    • http://muicuiu.dumb1.com/5a00a04a04a09/I-Michael-Bennett-Michael-Bennett-5-by-James-Patterson.pdf
    • http://muicuiu.dumb1.com/9a05a05a08/Revive-Us-Again-Vision-and-Action-in-Moral-Organizing-by-William-J-Barber-II.pdf
    • http://muicuiu.dumb1.com/1a00a03a07a07a07/The-Book-of-Virtues-by-William-J-Bennett.pdf
    • http://muicuiu.dumb1.com/2a03a00a09a03a07/Dave-Ramsey-s-Financial-Peace-University-Workbook-by-Dave-Ramsey.pdf
    • http://muicuiu.dumb1.com/6a02a09a07a06a06/The-American-Patriot-s-Almanac-by-William-J-Bennett.pdf
    • http://muicuiu.dumb1.com/7a03a07a07a01a05/A-Holy-Vision-for-a-Happy-Marriage-Building-a-Godly-Home-2-by-William-Gouge.pdf
    • http://muicuiu.dumb1.com/2a07a05a01a01a05/The-Celestine-Vision-Living-the-New-Spiritual-Awareness-by-James-Redfield.pdf
    • http://muicuiu.dumb1.com/3a06a08a04a02a03/The-True-Saint-Nicholas-Why-He-Matters-to-Christmas-by-William-J-Bennett.pdf
    • http://muicuiu.dumb1.com/2a07a00a01a07a02/Gone-Michael-Bennett-6-by-James-Patterson.pdf
    • http://muicuiu.dumb1.com/5a05a07a01a04a04/Vestiges-Of-Freedom-by-William-Venator.pdf
    • http://muicuiu.dumb1.com/8a00a07a07a02a09/King-James-The-Holy-Bible-the-bible-bible-bible-study-jesus-religion-religious-heaven-king-james-old-testament-new-testament-prayer-books-christian-by-Anonymous.pdf
    • http://muicuiu.dumb1.com/7a01a09a09a02a04/Agents-of-Terror-Queen-Elizabeth-1st-amp-St-Edmun