Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8604985513ef930…

MALICIOUS

PDF

21.0 KB Created: 2019-05-07 03:35:44 +01:00 Authoring application: mPDF 5.7
MD5: 87bcda91145e04eac14be531f6a82c3d SHA-1: 1db81551497ce356c8f29efcfeeb75bd15295f00 SHA-256: c8604985513ef930a3af40899e0cd126982b67799e3c6f469c1a5cc82fb4c6fd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious with a high probability. While the document body is heavily obfuscated, the presence of a link farm suggests an attempt to drive traffic or distribute further content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9935

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a03a06a01a09a08/Frame-Innovation-Create-New-Thinking-by-Design-by-Kees-Dorst.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a03a07a03/Notes-on-Design-How-Creative-Practice-Works-by-Kees-Dorst.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a03a07a02/Creative-Intelligence-Creating-the-Transdisciplinary-Professionals-of-the-Future-by-Kees-Dorst.pdf
    • http://muicuiu.dumb1.com/2a05a04a00a00a04/Signs-of-Intelligence-Understanding-Intelligent-Design-by-William-A-Dembski.pdf
    • http://muicuiu.dumb1.com/3a00a08a07a01a05/Under-the-Hood-Under-the-Law-2-by-Juanita-Kees.pdf
    • http://muicuiu.dumb1.com/1a01a00a06a07a03a04/Understanding-Understanding-Essays-on-Cybernetics-and-Cognition-by-Heinz-von-Foerster.pdf
    • http://muicuiu.dumb1.com/8a09a06a01a03a09/Mees-Kees-In-de-gloria-by-Mirjam-Oldenhave.pdf
    • http://muicuiu.dumb1.com/7a07a03a08a04a03/Understanding-Shingles-The-Understanding-Series-by-Fernando-Cr-tte.pdf
    • http://muicuiu.dumb1.com/6a01a07a09a06a00/Joris-Ivens-and-the-Documentary-Context-by-Kees-Bakker.pdf
    • http://muicuiu.dumb1.com/8a07a08a02a09a01/Felt-Filz-Art-Crafts-and-Design-Kunst-Kunsthandwerk-und-Design-by-Katharina-Thomas.pdf
    • http://muicuiu.dumb1.com/1a00a06a03a09a02a09/The-Design-of-Everyday-Things-Psychologie-und-Design-der-allt-glichen-Dinge-by-Donald-A-Norman.pdf
    • http://muicuiu.dumb1.com/7a02a07a04a02a05/Fingerprint-The-Art-of-Using-Hand-Made-Elements-in-Graphic-Design-by-Chen-Design-Associates.pdf
    • http://muicuiu.dumb1.com/1a00a00a01a04a07a04/Design-Your-Book-75-eBook-Cover-Design-Sites-That-Increase-Amazon-Sales-by-Greg-Strandberg.pdf
    • http://muicuiu.dumb1.com/8a07a09a02a06a07/What-They-Didn-t-Teach-You-In-Design-School-The-Essential-Guide-to-Growing-Your-Design-Career-by-Phil-Cleaver.pdf
    • http://muicuiu.dumb1.com/7a05a06a04a06a03/Analog-Circuit-Design-Robust-Design-Sigma-Delta-Converters-RFID-by-Herman-Casier.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a07/The-Design-Is-Murder-Murders-by-Design-5-by-Jean-Harrington.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a07a03/Design-Diva-Chloe-by-Design-1-by-Margaret-Gurevich.pdf
    • http://muicuiu.dumb1.com/1a00a00a02a04a08a02/Werkausgabe-by-Tankred-Dorst.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a04a06a04/Enchanted-Coast-by-Adrian-Dorst.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a03a06a07/Rainforest-America-by-Adrian-Dorst.pdf
    • http://muicuiu.dumb1.com/1a01a00a06a07a03a04/Understanding-Understanding-Essays-on-Cybernetics-and-Cognition-by-Heinz-von-Foerster