Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0e1492ae144912f…

MALICIOUS

PDF

22.3 KB Created: 2019-04-30 08:16:05 +01:00 Authoring application: mPDF 5.7
MD5: 8e25ecb1a017aaa23d6d329b5b2df55b SHA-1: dba569efd6814c38385f0e7dc3cbbd81bb876a1a SHA-256: c0e1492ae144912f560bd0adae082600cd826bfee6f5705db35ff77c15aea6df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these specific URLs are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a07a03a04a03a08/The-Infernals-A-Samuel-Johnson-Tale-Samuel-Johnson-vs-the-Devil-2-by-John-Connolly.pdf
    • http://muicuiu.dumb1.com/2a02a01a04a07a01/Hell-s-Bells-Samuel-Johnson-vs-the-Devil-Round-II-by-John-Connolly.pdf
    • http://muicuiu.dumb1.com/4a05a09a01a05a02/The-Vanity-of-Human-Wishes-by-Samuel-Johnson.pdf
    • http://muicuiu.dumb1.com/1a04a01a04a09a01/Samuel-Johnson-Is-Indignant-by-Lydia-Davis.pdf
    • http://muicuiu.dumb1.com/2a05a03a02a05a09/The-Life-of-Samuel-Johnson-by-James-Boswell.pdf
    • http://muicuiu.dumb1.com/1a09a05a09a02a00/Samuel-Johnson-The-Struggle-by-Jeffrey-Meyers.pdf
    • http://muicuiu.dumb1.com/2a09a02a06a06a07/A-Dictionary-of-the-English-Language-an-Anthology-by-Samuel-Johnson.pdf
    • http://muicuiu.dumb1.com/4a08a09a07a08a06/Redemption-Samuel-Elijah-Johnson-Series-Book-1-by-Troy-Lambert.pdf
    • http://muicuiu.dumb1.com/8a05a01a06a00a03/The-Life-of-Samuel-Johnson-LL-D-Comprehending-an-Account-of-His-Studies-and-Numerous-Works-in-Chronological-Order-A-Series-of-His-Epistolary-Correspondence-and-Conversations-with-Many-Eminent-Persons-And-Various-Original-Pieces-of-His-Composition-by-James-Boswell.pdf
    • http://muicuiu.dumb1.com/5a00a07a03a07a04/Rabbi-Samuel-Ben-Meir-s-Commentary-On-Genesis-An-Annotated-Translation-by-Samuel-ben-Meir.pdf
    • http://muicuiu.dumb1.com/5a09a07a08a01a01/Diary-of-Samuel-Pepys---Volume-26-January-February-1663-64-by-Samuel-Pepys.pdf
    • http://muicuiu.dumb1.com/6a03a06a03a09/The-World-Flesh-and-Devil-The-Life-and-Opinions-of-Samuel-Marsden-in-England-and-the-Antipodes-1765-1838-by-Andrew-Sharp.pdf
    • http://muicuiu.dumb1.com/1a04a02a01a07a02/A-True-Likeness-The-Black-South-of-Richard-Samuel-Roberts-1920-1936-by-Richard-Samuel-Roberts.pdf
    • http://muicuiu.dumb1.com/4a01a05a08a03a03/Ancrom-s-Tale-by-W-A-Johnson.pdf
    • http://muicuiu.dumb1.com/1a00a09a09a00a00a03/Crazy-Rich-Power-Scandal-and-Tragedy-Inside-the-Johnson-amp-Johnson-Dynasty-by-Jerry-Oppenheimer.pdf
    • http://muicuiu.dumb1.com/1a05a08a08a01a03/Dolly-and-the-Bird-of-Paradise-Johnson-Johnson-6-by-Dorothy-Dunnett.pdf
    • http://muicuiu.dumb1.com/1a08a02a08a08a00/The-Devil-and-Danielle-Webster-A-Novella-by-Peter-Johnson.pdf
    • http://muicuiu.dumb1.com/1a03a09a06a05a03/I-Married-Adventure-The-Lives-of-Martin-and-Osa-Johnson-by-Osa-Johnson.pdf
    • http://muicuiu.dumb1.com/2a06a09a02a02a01/Shower-Power-Peephole-Tug-Johnson-s-Hot-Tales-3-by-Tug-Johnson.pdf
    • http://muicuiu.dumb1.com/3a07a04a09a09a04/Marina-s-Whale-of-a-Tale-by-Charles-A-Johnson.pdf
    • http://muicuiu.dumb1.com/8a05a01a06a00a03/The-Life-of-Samuel-Johnson-LL-D-Comprehending-an-Account