Malicious PDF — malware analysis report

Static analysis result for SHA-256 c08daae700662388…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 00:58:03 +01:00 Authoring application: mPDF 5.7
MD5: 5e13fa42ff28a6ab299ae730239c63f1 SHA-1: a3cb9af035ff5025a1720eb86f4617a02f0f16f9 SHA-256: c08daae700662388679a7f80072ac24c147a737d7f15205ad3306384b940717d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier flagged this as malicious, the specific URLs extracted are currently marked as benign. The primary attack pattern appears to be a link farm designed to redirect users, potentially to malicious content or for SEO manipulation. No scripts were extracted, limiting further analysis of the payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a05a08a02a08a04/Chantilly-s-Cowboy-Sisters-of-McDougal-Ranch-1-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/3a05a08a02a08a05/Florentine-s-Hero-Sisters-of-McDougal-Ranch-4-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/2a07a03a08a08a08/Kissed-by-a-Cowboy-Four-of-Hearts-Ranch-3-by-Debra-Clopton.pdf
    • http://muicuiu.dumb1.com/1a04a08a06a03a08/Breathing-His-Air-Bantorus-MC-1-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/2a09a07a01a05a00/Aching-To-Exhale-Bantorus-MC-2-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/3a05a07a09a04a09/Grasping-For-Freedom-Bantorus-MC-4-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/3a05a07a09a05a04/Fighting-To-Ride-Bantorus-MC-5-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/3a05a08a01a01a08/Secretly-Playing-For-Hearts-4-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/3a05a08a00a07a03/Ride-Free-The-Chromes-and-Wheels-Gang-2-by-Debra-Kayn.pdf
    • http://muicuiu.dumb1.com/1a08a08a00a08a01/Betting-on-Hope-Four-of-Hearts-Ranch-Romance-1-by-Debra-Clopton.pdf
    • http://muicuiu.dumb1.com/7a02a06a03a09a05/The-Reluctant-Cowboy-Morgan-Ranch-1-by-Kate-Pearce.pdf
    • http://muicuiu.dumb1.com/1a02a09a05a04a04/Tempting-the-Cowboy-Paint-River-Ranch-1-by-Elizabeth-Otto.pdf
    • http://muicuiu.dumb1.com/2a05a06a01a02a03/How-to-Kiss-a-Cowboy-Cowboys-of-Decker-Ranch-2-by-Joanne-Kennedy.pdf
    • http://muicuiu.dumb1.com/3a04a07a09a07a02/One-Night-with-a-Cowboy-Paint-River-Ranch-2-by-Elizabeth-Otto.pdf
    • http://muicuiu.dumb1.com/4a05a08a03a04a09/The-Cowboy-s-Christmas-Gift-Crooked-Valley-Ranch-1-by-Donna-Alward.pdf
    • http://muicuiu.dumb1.com/2a02a05a02a00a09/A-True-Cowboy-Christmas-Cold-River-Ranch-1-by-Caitlin-Crews.pdf
    • http://muicuiu.dumb1.com/5a04a00a09a03a06/McDougal-Littell-Pre-Algebra-Special-Activities-Book-by-McDougal-Littell.pdf
    • http://muicuiu.dumb1.com/5a09a09a04a07a06/Dead-Sisters-The-Thunder-Perfect-Mind-by-Debra-Manion.pdf
    • http://muicuiu.dumb1.com/3a04a08a01a02a08/Cowboy-His-Ranch-His-Rules-His-Secrets-Taking-Charge-Blazing-Romance-Suspens-1-by-Maggie-Carpenter.pdf
    • http://muicuiu.dumb1.com/4a03a03a07a05a08/Tempest-by-Chantilly-White.pdf