Malicious PDF — malware analysis report

Static analysis result for SHA-256 c803a12ad4988715…

MALICIOUS

PDF

18.8 KB Created: 2019-05-07 09:07:06 +01:00 Authoring application: mPDF 5.7
MD5: c769ce5d970539650060c948f6fb0e2f SHA-1: d476bd78c34305f0d4e308ed0bf31fad3a2677b7 SHA-256: c803a12ad49887155d2adad8d2ec77680700d278f147a8584855d83c761adb06
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves tricking users into clicking through a link farm, potentially leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a02a05a01a04a08/Agent-Garbo-The-Brilliant-Eccentric-Secret-Agent-Who-Tricked-Hitler-and-Saved-D-Day-by-Stephan-Talty.pdf
    • http://muicuiu.dumb1.com/6a08a09a03a09a08/Chevalier-d-Eon-agent-secret-du-Roi-tome-1---Le-masque-Chevalier-d-Eon-agent-secret-du-Roi-by-Silvestre.pdf
    • http://muicuiu.dumb1.com/4a08a02a08a00/Agent-Zigzag-The-True-Wartime-Story-of-Eddie-Chapman-The-Most-Notorious-Double-Agent-of-World-War-II-by-Ben-Macintyre.pdf
    • http://muicuiu.dumb1.com/8a06a08a00a00/Polity-Agent-Agent-Cormac-4-by-Neal-Asher.pdf
    • http://muicuiu.dumb1.com/3a06a07a04/The-Temporary-Agent-The-Agent-1-by-Daniel-Judson.pdf
    • http://muicuiu.dumb1.com/5a01a04a01a00/Agent-21-Agent-21-1-by-Chris-Ryan.pdf
    • http://muicuiu.dumb1.com/5a08a00a05a04a08/Secret-Agent-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/2a03a09a05a03a03/Julian-Secret-Agent-by-Ann-Cameron.pdf
    • http://muicuiu.dumb1.com/2a01a06a04a04a08/Secret-Agent-Man-by-Diana-Palmer.pdf
    • http://muicuiu.dumb1.com/2a02a07a06a07a04/The-Secret-Agent-A-Simple-Tale-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/4a01a00a00a02a01/The-Secret-Agent-A-Simple-Tale-by-Joseph-Conrad.pdf
    • http://muicuiu.dumb1.com/5a05a04a04a09a05/Secret-Agent-Josephine-s-Numbers-by-Brenda-Ponnay.pdf
    • http://muicuiu.dumb1.com/1a04a08a00a01a01/The-Real-Story-of-a-Secret-Agent-by-Ahmad-Mohamad-Ali.pdf
    • http://muicuiu.dumb1.com/2a09a06a05a02a05/Impetuous-R-Secret-Agent-by-Jane-Leslie-Conly.pdf
    • http://muicuiu.dumb1.com/3a00a06a07a00a09/Secret-Agent-Affair-The-Doctors-Pulaski-5-by-Marie-Ferrarella.pdf
    • http://muicuiu.dumb1.com/2a09a06a08a00a04/Secret-Agent-Secretary-ICE-Black-Ops-Defenders-2-by-Melissa-Cutler.pdf
    • http://muicuiu.dumb1.com/2a04a07a03a08a07/Our-Man-in-Charleston-Britain-s-Secret-Agent-in-the-Civil-War-South-by-Christopher-Dickey.pdf
    • http://muicuiu.dumb1.com/1a01a07a00a09a00a02/Secret-Agent-Santa-Brothers-in-Arms-Retribution-4-by-Carol-Ericson.pdf
    • http://muicuiu.dumb1.com/2a06a03a08a08a02/The-Prime-Minister-s-Secret-Agent-Maggie-Hope-4-by-Susan-Elia-MacNeal.pdf
    • http://muicuiu.dumb1.com/1a07a04a03a05a05/The-Prime-Minister-s-Secret-Agent-Maggie-Hope-Mystery-4-by-Susan-Elia-MacNeal.pdf
    • http://muicuiu.dumb1.com/3a06a07a04/The-Temporary-Agent-The-Agent-1-b