Malicious PDF — malware analysis report

Static analysis result for SHA-256 c466ba4406b31e5e…

MALICIOUS

PDF

16.5 KB Created: 2019-05-02 18:10:33 +01:00 Authoring application: mPDF 5.7
MD5: e66c758ae2f81cd48e3f315279fb11d6 SHA-1: e653c041841095c7ae6518cd602fee3db7b17202 SHA-256: c466ba4406b31e5e39f57c6982fddcecede7660cea8030c8673b7c9ad201ff6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a08a05a05a01a05/The-Reign-of-Napoleon-Bonaparte-by-Robert-B-Asprey.pdf
    • http://muicuiu.dumb1.com/1a00a04a02a06a07a06/Renaissance-Warrior-and-Patron-The-Reign-of-Francis-I-by-Robert-J-Knecht.pdf
    • http://muicuiu.dumb1.com/5a04a08a01a02a00/Edouard-Manet-by-Richard-Wrigley.pdf
    • http://muicuiu.dumb1.com/3a04a05a03a00a06/Domnall-and-the-Borrowed-Child-by-Sylvia-Spruck-Wrigley.pdf
    • http://muicuiu.dumb1.com/5a08a03a09a03a05/The-Reign-of-Mathias-The-Chronicles-of-Mathias-Book-2-by-Robert-McDermott.pdf
    • http://muicuiu.dumb1.com/1a08a08a03a05a07/Snakes-by-Nic-Bishop.pdf
    • http://muicuiu.dumb1.com/3a00a08a04a05a01/Reign-of-Shadows-Reign-of-Shadows-1-by-Sophie-Jordan.pdf
    • http://muicuiu.dumb1.com/9a02a05a03a09a00/A-Rave-of-Snakes-by-Skip-Press.pdf
    • http://muicuiu.dumb1.com/6a03a08a05a09/How-to-Be-Dead-in-a-Year-of-Snakes-by-Chris-Tse.pdf
    • http://muicuiu.dumb1.com/1a03a03a09a00a00/Lady-of-the-Snakes-by-Rachel-Pastan.pdf
    • http://muicuiu.dumb1.com/9a00a08a02a05a07/Deadly-Snakes-by-Lisa-McCourt.pdf
    • http://muicuiu.dumb1.com/3a03a02a08a06a04/No-Nightingales-No-Snakes-by-Maeve-Binchy.pdf
    • http://muicuiu.dumb1.com/4a08a02a01a05/A-Feast-of-Snakes-by-Harry-Crews.pdf
    • http://muicuiu.dumb1.com/2a03a08a06a02a06/Snakes-in-Suits-When-Psychopaths-Go-to-Work-by-Paul-Babiak.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a01a02a02/Snakes-of-India-The-Field-Guide-by-Romulus-Earl-Whitaker.pdf
    • http://muicuiu.dumb1.com/4a02a02a08a02a01/The-Hopes-of-Snakes-And-Other-Tales-from-the-Urban-Landscape-by-Lisa-Couturier.pdf
    • http://muicuiu.dumb1.com/6a04a07a04a07/Don-t-Sleep-There-Are-Snakes-Life-and-Language-in-the-Amazonian-Jungle-by-Daniel-L-Everett.pdf
    • http://muicuiu.dumb1.com/5a02a04a05a08a06/Snakes-Guillotines-Electric-Chairs-My-Adventures-in-The-Alice-Cooper-Group-by-Dennis-Dunaway.pdf
    • http://muicuiu.dumb1.com/1a08a07a09a00a07/Reign-of-Ash-The-Chosen-2-by-Meg-Anne.pdf
    • http://muicuiu.dumb1.com/7a00a05a02a07a05/Reign-Over-Me-by-Rebecca-Brochu.pdf