Malicious PDF — malware analysis report

Static analysis result for SHA-256 c59f7b354bc0cf03…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 04:10:51 +01:00 Authoring application: mPDF 5.7
MD5: 890d2c12afc5eef5c95d9e2ad99abca3 SHA-1: eded0337c5df50e062a2f4ca58ca0e0dc53c246e SHA-256: c59f7b354bc0cf036d6d09e962c440237c3392e5fc5c41f69f04c41d67f440bd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs were classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a02a01a06a03a02/Wrestling-With-Desire-by-D-H-Starr.pdf
    • http://muicuiu.dumb1.com/2a08a06a01a00a01/Wrestling-with-Love-Wrestling-2-by-D-H-Starr.pdf
    • http://muicuiu.dumb1.com/7a01a09a05a05a09/Combat-Zone-Wrestling-Czw-Cage-of-Death-Combat-Zone-Wrestling-Championships-Combat-Zone-Wrestling-Shows-List-of-Czw-World-Tag-Team-Champi-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/2a05a08a05a03a01/The-Starr-Report-The-Findings-Of-Independent-Counsel-Kenneth-Starr-On-President-Clinton-And-The-Lewinsky-Affair-by-Kenneth-W-Starr.pdf
    • http://muicuiu.dumb1.com/6a08a01a09a01a08/WRESTLING-Catch-As-Catch-Can-Style---23-Illustrated-Wrestling-Moves-by-Edward-Hitchcock-Jr-.pdf
    • http://muicuiu.dumb1.com/1a03a09a00a03a03/David-Starr-Space-Ranger-Lucky-Starr-1-by-Isaac-Asimov.pdf
    • http://muicuiu.dumb1.com/5a09a05a07a01/Lucky-Starr-and-the-Oceans-of-Venus-Lucky-Starr-3-by-Isaac-Asimov.pdf
    • http://muicuiu.dumb1.com/3a06a07a07a02a04/Desire-for-Three-Winning-Back-Jesse-More-Desire-Oklahoma-1-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/2a05a01a07a02a02/Rules-Of-Desire-Desire-Oklahoma-4-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/2a05a02a04a07a05/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/4a01a01a05a09a05/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/3a08a06a01a09a09/Submission-to-Desire-Desire-Oklahoma-7-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/5a02a06a02a02a05/Hint-of-Desire-Desire-1-by-Lavinia-Kent.pdf
    • http://muicuiu.dumb1.com/5a02a06a02a09a03/Price-of-Desire-Desire-2-by-Lavinia-Kent.pdf
    • http://muicuiu.dumb1.com/2a05a01a04a02a05/Desire-for-Three-Desire-Oklahoma-1-by-Leah-Brooke.pdf
    • http://muicuiu.dumb1.com/2a00a06a08a06a01/Wrestling-This-by-Dan-Sexton.pdf
    • http://muicuiu.dumb1.com/6a03a01a03a02/Wrestling-with-the-Angel-by-Michael-King.pdf
    • http://muicuiu.dumb1.com/1a09a09a01a02a06/Wrestling-Demons-by-Xavier-Mayne.pdf
    • http://muicuiu.dumb1.com/7a08a04a03a04a07/Wrestling-with-Ghosts-by-Jorge-Conesa-Sevilla.pdf
    • http://muicuiu.dumb1.com/7a09a04a08a06a06/The-Complete-Idiot-s-Guide-to-Pro-Wrestling-by-Lou-Albano.pdf
    • http://muicuiu.dumb1.com/2a05a08a05a03a01/The-Starr-Report-The-Findings-Of-Independent-Counsel-Kenneth-Starr-On-President-Clinton-And-The-Lewinsky-Affair-by-Kenneth-W-Starr