Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2eca7ff0d629125…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 04:11:57 +01:00 Authoring application: mPDF 5.7
MD5: 896ff59c232536e7ff9b50cf8f5221de SHA-1: b4a90feb540cfd396b994a1636fdea07f0b0a364 SHA-256: c2eca7ff0d629125c4a9c6b54afe073ed42e43a6886348c6d27f5765f52e167f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely part of a link farm, potentially for SEO manipulation or to distribute malicious content. While no scripts were extracted, the sheer volume of links and the ML classification suggest a malicious intent, possibly to redirect users to phishing sites or download further malware. The URLs themselves appear to be benign, but their aggregation within the PDF is suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a07a04a01a05/Josef-Anni-Albers-Designs-for-Living-by-Nicholas-Fox-Weber.pdf
    • http://muicuiu.dumb1.com/1a01a09a00a01a08a05/Architecture-and-Interaction-Human-Computer-Interaction-in-Space-and-Place-by-Nicholas-Dalton.pdf
    • http://muicuiu.dumb1.com/8a02a02a00a05a02/Models-of-Employee-Participation-in-a-Changing-Global-Environment-Diversity-and-Interaction-Diversity-and-Interaction-by-Ray-Markey.pdf
    • http://muicuiu.dumb1.com/1a00a00a06a02a09a07/Color-Blind-The-Forgotten-Team-That-Broke-Baseball-s-Color-Line-by-Tom-Dunkel.pdf
    • http://muicuiu.dumb1.com/4a06a09a03a08a05/The-Color-of-a-Memory-The-Color-of-Heaven-Series-Volume-5-by-Julianne-MacLean.pdf
    • http://muicuiu.dumb1.com/1a06a09a01a00a07/The-Color-of-Hope-The-Color-of-Heaven-3-by-Julianne-MacLean.pdf
    • http://muicuiu.dumb1.com/1a04a05a06a02a00/Color-of-Forgiveness-Color-2-by-Madeleine-Beckett.pdf
    • http://muicuiu.dumb1.com/1a00a09a05a07a04a05/Jan-Hus-Anteil-an-der-hussitischen-Revolution-by-Daniel-Albers.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a02/Nackt-und-Schamlos-Sexgeschichten-by-Hans-Albers.pdf
    • http://muicuiu.dumb1.com/8a08a02a08a01a06/Entscheidungshilfen-Fur-Den-Personlichen-Verkauf-by-Sonke-Albers.pdf
    • http://muicuiu.dumb1.com/9a00a06a03a07a06/Die-Darstellung-des-L-wen-in-Hartmanns-von-Aue-Iwein-by-Daniel-Albers.pdf
    • http://muicuiu.dumb1.com/8a08a02a08a01a07/Cross-Functional-Innovation-Management-Perspectives-From-Different-Disciplines-by-Sonke-Albers.pdf
    • http://muicuiu.dumb1.com/4a05a03a05a02a04/But-I-Deserve-This-Chocolate-The-Fifty-Most-Common-Diet-Derailing-Excuses-and-How-to-Outwit-Them-by-Susan-Albers.pdf
    • http://muicuiu.dumb1.com/7a04a05a00a07a02/Interaction-Revision-de-grammaire-fran-aise-by-Susan-St-Onge.pdf
    • http://muicuiu.dumb1.com/1a00a03a03a08a02a04/The-Art-and-Science-of-Interface-and-Interaction-Design-Vol-1-v-1-by-Christa-Sommerer.pdf
    • http://muicuiu.dumb1.com/1a01a06a08a02a02a05/Superposition-and-Interaction-Coherence-in-Physics-by-Richard-Schlegel.pdf
    • http://muicuiu.dumb1.com/8a09a02a08a07a02/Human-Computer-Interaction-From-Voltage-To-Knowledge-by-Jurek-Kirakowski.pdf
    • http://muicuiu.dumb1.com/5a04a08a04a06a03/Interpersonal-Adaptation-Dyadic-Interaction-Patterns-by-Judee-K-Burgoon.pdf
    • http://muicuiu.dumb1.com/9a00a03a07a05a04/The-Resonant-Interface-Hci-Foundations-for-Interaction-Design-by-Steven-Heim.pdf
    • http://muicuiu.dumb1.com/6a03a09a01a05a01/Research-Methods-in-Human-Computer-Interaction-by-Jonathan-Lazar.pdf
    • http://muicuiu.dumb1.com/1a06a09a01a00a07/The-Color-of-Hope-The-Color-of-Heaven-3-by-Juli