Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3696f27bac3f41e…

MALICIOUS

PDF

23.2 KB Created: 2019-04-30 04:37:28 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-28
MD5: d6ef070e22ee2fe01670b2cd623ef6a7 SHA-1: 24b1fc1bf235fcb330126df9dcf0b23322e62afb SHA-256: c3696f27bac3f41e18e3755f2ba522c662de553ab68021e8fbd99538b5d0e77e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a02a03a00a09a06/Gentlewomen-and-Learned-Ladies-Women-and-Elite-Formation-in-Eighteenth-Century-Philadelphia-by-Sarah-Fatherly.pdf In PDF document text
    • http://muicuiu.dumb1.com/1a01a07a04a00a07a08/Studies-in-Eighteenth-Century-Culture-Volume-I-The-Modernity-Of-The-Eighteenth-Century-by-Louis-T-Milic.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a08a00a02a08/Eighteenth-Century-Ceramics-Products-for-a-Civilised-Society-by-Sarah-Richards.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a02a05a06a00/Citoyennes-Women-and-the-Ideal-of-Citizenship-in-Eighteenth-Century-France-by-Annie-Smart.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a06a02a09a07a02/Eighteenth-Century-Women-Poets-and-Their-Poetry-Inventing-Agency-Inventing-Genre-by-Paula-R-Backscheider.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a00a01a07a01/Eighteenth-Century-British-Midwifery-Part-I-by-Pam-Lieske.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a00a01a06a03/Eighteenth-Century-British-Midwifery-Part-II-by-Pam-Lieske.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a00a02a02a07/Eighteenth-Century-British-Midwifery-Parts-I-II-and-III-by-Pam-Lieske.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a02a03a03a08a07/Lord-Hervey-Eighteenth-Century-Courtier-by-Halsband.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a07a08a05a06a03/A-Photographic-Guide-to-Marionettes-in-the-Sixteenth-to-the-Eighteenth-Century-by-Max-Von-Boehn.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a07a08a04a03a01/Modes-amp-Manners-From-the-Middle-Ages-to-the-End-of-the-Eighteenth-Century-by-Max-Von-Boehn.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a09a02a07a03a06/The-Beggar-s-Opera-and-other-Eighteenth-Century-plays-by-John-Hampden.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a01a09a05a01a05/John-Law-A-Scottish-Adventurer-in-the-Eighteenth-Century-by-James-Buchan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a06a06a08a06a06/Dangerous-Liaisons-Fashion-and-Furniture-in-the-Eighteenth-Century-by-Harold-Koda.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a08a05a02a09a07/The-British-Navy-and-the-Use-of-Naval-Power-in-the-Eighteenth-Century-by-Jeremy-Black.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a01a04a05a09a02/Transformations-of-the-German-Novel--Simplicissimus--In-Eighteenth-Century-Adaptations-by-Monique-Rinere.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a09a02a02a01a03/Great-Expectations-Futurity-in-the-Long-Eighteenth-Century-by-Mascha-Hansen.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a01a03a09a06a08/Ballad-Criticism-in-Scandinavia-amp-Great-Britain-During-the-Eighteenth-Century-by-Sigurd-B-Hustvedt.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a04a07a00a06a05/Subversive-Words-Public-Opinion-In-Eighteenth-Century-France-by-Arlette-Farge.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a02a03a03a03a08/The-Mitred-Earl-An-Eighteenth-century-Eccentric---Frederick-Hervey-by-Brian-Fothergill.pdfIn PDF document text