Malicious PDF — malware analysis report

Static analysis result for SHA-256 c86fdefe85406170…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 04:29:42 +01:00 Authoring application: mPDF 5.7
MD5: cb9a59bda3f5e48ee32568a0316c2466 SHA-1: aadf5f1d87756e5deef9f6dd8ad3571198076fd1 SHA-256: c86fdefe85406170c36c40334794d17957eb8607bc52e0931ae0b99a99e7f2fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and a critical heuristic for containing a large number of external links, suggesting a link farm or redirection scheme. While the extracted URLs themselves are currently marked as benign, the sheer volume and the heuristic's classification indicate a malicious intent, likely to lure users to malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a02a09a08a09/River-God-Ancient-Egypt-1-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/4a09a06a01a01a06/River-God-A-Novel-of-Ancient-Egypt-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/1a09a04a05a09a04/River-God-Ancient-Egypt-1-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/7a05a02a05a06a06/The-Treasures-of-Ancient-Egypt-From-the-Rosetta-Stone-to-the-Tomb-of-Tutankhamun---The-Search-for-the-Riches-of-Ancient-Egypt-by-Jaromir-Malek.pdf
    • http://muicuiu.dumb1.com/5a00a02a09a09a07/The-Art-and-Architecture-of-Ancient-Egypt-by-W-Stevenson-Smith.pdf
    • http://muicuiu.dumb1.com/5a00a02a06a09a00/First-Civilizations-Ancient-Mesopotamia-and-Ancient-Egypt-by-Robert-Chadwick.pdf
    • http://muicuiu.dumb1.com/6a00a08a06a03a07/Rivers-of-Norfolk-River-Yare-River-Bure-River-Waveney-River-Nene-River-Ant-River-Thurne-North-Walsham-amp-Dilham-Canal-River-Wensum-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/2a08a03a04a08a07/Ancient-Egypt-by-David-P-Silverman.pdf
    • http://muicuiu.dumb1.com/8a02a01a02a07a02/Ancient-Egypt-by-Robert-Coupe.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a09a09/Ancient-Egypt-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/5a00a02a02a07a09/Women-in-Ancient-Egypt-by-Gay-Robins.pdf
    • http://muicuiu.dumb1.com/1a02a09a07a07a00/Eagle-in-the-Sky-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/5a00a02a04a05a08/An-introduction-to-Ancient-Egypt-by-James-Putnam.pdf
    • http://muicuiu.dumb1.com/4a00a05a07a06a00/Ancient-Egypt-Mesopotamia-Persia-by-Koutsoukis.pdf
    • http://muicuiu.dumb1.com/9a05a04a09a02a00/Conceptions-of-God-in-Ancient-Egypt-by-Erik-Hornung.pdf
    • http://muicuiu.dumb1.com/9a00a03a00a09a04/A-History-of-Ancient-Egypt-by-Nicolas-Grimal.pdf
    • http://muicuiu.dumb1.com/5a00a02a02a07a07/The-Oxford-History-of-Ancient-Egypt-by-Ian-Shaw.pdf
    • http://muicuiu.dumb1.com/1a00a07a02a05a08/The-Cat-of-Bubastes-A-Tale-of-Ancient-Egypt-by-G-A-Henty.pdf
    • http://muicuiu.dumb1.com/6a07a07a07a06a00/Gold-Mine-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/4a03a07a01a05/Elephant-Song-by-Wilbur-Smith.pdf
    • http://muicuiu.dumb1.com/6a00a08a06a03a07/Rivers-of-Norfolk-River-Yare-River-Bure-River-Waveney-River-Nene-River-Ant-River-Thurne-North-Walsham-amp-Dilham-Canal-Riv