Malicious PDF — malware analysis report

Static analysis result for SHA-256 c292cb19876471cb…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 04:14:49 +01:00 Authoring application: mPDF 5.7
MD5: 67b6ab7d133b8cffcb4d8867b58f4bb3 SHA-1: 06a22f6a2806588c7f08cbb3cb4c796c349dd79a SHA-256: c292cb19876471cbc05f37fec275aad63151fa87afe932a4623361acd247ab8f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a link farm or redirection strategy. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a06a09a02a08/Theodor-Herzl---Gesammelte-Werke-by-Theodor-Herzl.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a09a09/Solon-in-Lydien-Herzl-Theodor-by-Theodor-Herzl.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a08a07a08/Herzl-King-Of-The-Jews-A-Psychoanalytic-Biography-Of-Theodor-Herzl-by-Avner-Falk.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a08a07a09/Herzl-King-of-the-Jews-A-Psychoanalytic-Biography-of-Theodor-Herzl-by-Avner-Falk.pdf
    • http://muicuiu.dumb1.com/6a09a09a03a02a05/Herzl-Theodor-Herzl-and-the-Foundation-of-the-Jewish-State-by-Shlomo-Avineri.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a09a03/Diaries-of-Theodor-Herzl-by-Theodor-Herzl.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a05a04/Theodor-Herzl-the-Jew-and-the-Man-by-Oscar-Benjamin-Frankl.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a02a06/Theodor-Herzl-and-the-Origins-of-Zionism-by-Ritchie-Robertson.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a02a00a02/Passover-Its-History-And-Traditions-by-Theodor-Herzl-Gaster.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a09a07/Theodor-Herzl-And-The-Zionist-Dream-by-Julius-H-Schoeps.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a07a00/Theodor-Herzl-Founder-of-Political-Zionism-by-Israel-Cohen.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a06a04/Theodor-Herzl-Visionary-of-the-Jewish-State-by-Gideon-Shimoni.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a06a08/The-Holy-and-the-Profane-Evolution-of-Jewish-Folkways-by-Theodor-Herzl-Gaster.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a01a09a00/Theodor-Herzl-and-Austria-A-Century-Later---An-Essay-By-Steven-Beller-by-Steven-Beller.pdf
    • http://muicuiu.dumb1.com/1a00a01a05a04a02a09/Briefe-Herrmann-Theodor-Goltdammers-an-Karl-Josef-Anton-Mittermaier-Juristische-Briefwechsel-Des-19-Jahrhunderts-by-Theodor-Goltdammer.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a05a06/Dr-Teodoro-Herzl-by-Dante-A-Lattes.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a09a08/Herzl-and-Mahler-Interfaces-by-Chaim-Den-Heijer.pdf
    • http://muicuiu.dumb1.com/1a00a00a02a09a09a01/Gesammelte-Werke-Gedichte-Dramen-Historiografische-Werke-M-rchen-Biografie-Vollst-ndige-Ausgaben-Der-romantische-dipus-Rosensohn-Geschichte-Sonette-Oden-Hymnen-by-August-von-Platen.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a09a01/Star-of-Jordan-The-Life-of-Theodore-Herzl-by-Josef-Patai.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a09a03a01/Herzl-s-Journey-Conversations-With-A-Zionist-Legend-by-Bernard-Zissman.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a02a00a02/Passover-Its-