Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7cb595eb7e7f505…

MALICIOUS

PDF

19.7 KB Created: 2019-04-30 02:08:30 +01:00 Authoring application: mPDF 5.7
MD5: 5fd818623f5203d5185761ae53395f76 SHA-1: 20ff3b49467171e9dd5f433bb17f444337b8d35b SHA-256: c7cb595eb7e7f505aa74488efd1d52482d5cc61263ec62eb86e6569486be06df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly supports the malicious verdict. While no scripts were extracted, the PDF structure itself indicates a malicious intent to redirect users to a link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a06a04a06a08a00/Hoffman-s-hunger-by-Leon-de-Winter.pdf
    • http://muicuiu.dumb1.com/7a09a00a05a04/Zoeken-naar-Eileen-W-by-Leon-de-Winter.pdf
    • http://muicuiu.dumb1.com/1a00a08a01a04a06a00/The-Man-Who-Fed-the-World-Nobel-Peace-Prize-Laureate-Norman-Borlang-and-His-Battle-to-End-World-Hunger-by-Leon-Hesser.pdf
    • http://muicuiu.dumb1.com/5a05a05a02a05a01/The-Hunger-Games-The-Interactive-Quiz-Book-The-Hunger-Games-Series-1-by-M-J-Roan.pdf
    • http://muicuiu.dumb1.com/1a01a00a04a07a04a00/Leon-Degrelle-and-the-Rexist-Party-1935-1940-by-Leon-Degrelle.pdf
    • http://muicuiu.dumb1.com/9a09a02a09a02a05/Another-Day-in-Winter-NEW-from-the-No1-Bestselling-Author-A-perfect-winter-treat-A-Winter-Day-Book-Book-2-by-Shari-Low.pdf
    • http://muicuiu.dumb1.com/5a06a01a08a00/The-Hunger-Games-The-Hunger-Games-1-by-Suzanne-Collins.pdf
    • http://muicuiu.dumb1.com/3a07a01a09a05a04/The-Hunger-Games-The-Hunger-Games-1-by-Suzanne-Collins.pdf
    • http://muicuiu.dumb1.com/1a00a01a02a03a08a04/Jilliane-Hoffman-Books-2017-Checklist-Reading-Order-of-C-J-Townsend-Series-FBI-Agent-Bobby-Dees-Series-and-List-of-All-Jilliane-Hoffman-Books-by-Platinum-List.pdf
    • http://muicuiu.dumb1.com/1a01a00a04a07a00a06/In-Memorium-Leon-Degrelle-Et-Le-Rexisme-by-Leon-Degrelle.pdf
    • http://muicuiu.dumb1.com/6a08a00a09a03a06/Ossie-Osman-Leon-My-Autobiography-by-Leon-Osman.pdf
    • http://muicuiu.dumb1.com/2a02a00a02a07a06/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://muicuiu.dumb1.com/1a05a05a07a00a09/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://muicuiu.dumb1.com/8a04a09a05a01a04/Winter-Solstice-Winter-Viking-Blood-Saga-1-by-E-J-Squires.pdf
    • http://muicuiu.dumb1.com/1a05a05a07a02a07/Winter-s-Storm-Retribution-Winter-s-Saga-2-by-Karen-Luellen.pdf
    • http://muicuiu.dumb1.com/3a06a05a04a09a00/Call-of-Winter-Winter-Princess-Serial-1-by-Skye-MacKinnon.pdf
    • http://muicuiu.dumb1.com/4a02a03a03a02a07/One-Christmas-In-Winter-Winter-Montana-1-by-Bell-Renshaw.pdf
    • http://muicuiu.dumb1.com/3a00a06a08a01a02/Red-Winter-Red-Winter-Trilogy-1-by-Annette-Marie.pdf
    • http://muicuiu.dumb1.com/5a02a08a01/The-Marvelous-Misadventures-of-Ingrid-Winter-Ingrid-Winter-Misadventure-1-by-J-S-Drangsholt.pdf
    • http://muicuiu.dumb1.com/3a00a02a01a07a05/As-Is-by-William-M-Hoffman.pdf
    • http://muicuiu.dumb1.com/9a09a02a09a02a05/Another-Day-in-Winter-NEW-from-the-No1-Bestselling-Author-A-perfect-winter-treat-A-Winter-Day-Book-