Malicious PDF — malware analysis report

Static analysis result for SHA-256 c941f88969718c32…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 04:52:42 +01:00 Authoring application: mPDF 5.7
MD5: 85aa077b8f77b07509e5a484297ce963 SHA-1: 224517017749ad667b6b16a1a69b1f2b6a30b87a SHA-256: c941f88969718c322c6da8ee2526d271160b802c47f29d398eb12419fb1d0530
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the ML classifier flagged this as malicious, the majority of the extracted URLs are marked as confirmed benign. The document body is heavily obfuscated and unreadable, preventing a clear understanding of its intended purpose beyond link distribution. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a06a00a00a08/Todo-in-Tuscany-The-Dog-at-the-Villa-by-Louise-Badger.pdf
    • http://muicuiu.dumb1.com/8a06a08a01a00a03/Bauwerk-Des-Historismus-in-Nordrhein-Westfalen-Schloss-Landsberg-Villa-Cassalette-Hagen-Hauptbahnhof-Konigsallee-13-Villa-Klausener-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/7a07a09a03a08a07/NADA-Por-Obligacion-Todo-Con-Ilusion-by-Oriol-Pujol.pdf
    • http://muicuiu.dumb1.com/6a06a02a08a09/Todo-lo-que-podr-amos-haber-sido-t-y-yo-si-no-fu-ramos-t-y-yo-by-Albert-Espinosa.pdf
    • http://muicuiu.dumb1.com/4a04a01a02a03/Si-t-me-dices-ven-lo-dejo-todo-pero-dime-ven-by-Albert-Espinosa.pdf
    • http://muicuiu.dumb1.com/7a09a07a05a02/The-Badger-Confession-by-J-A-Ricketts.pdf
    • http://muicuiu.dumb1.com/8a09a01a00a06/Yesterday-Once-More-by-Karen-D-Badger.pdf
    • http://muicuiu.dumb1.com/6a05a06a09a05/Genie-in-Training-by-Meredith-Badger.pdf
    • http://muicuiu.dumb1.com/1a08a00a05a02a09/State-of-Grace-by-Hilary-Badger.pdf
    • http://muicuiu.dumb1.com/1a00a01a02a04a06a00/A-Matter-of-Marnie-by-Rosemary-Badger.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a01a03a04/The-New-Deal-The-Depression-Years-1933-40-by-Anthony-J-Badger.pdf
    • http://muicuiu.dumb1.com/3a07a08a09a07a03/Louise-s-Gamble-Louise-Pearlie-2-by-Sarah-R-Shaber.pdf
    • http://muicuiu.dumb1.com/3a03a07a03a07a07/The-Hills-of-Tuscany-by-Ferenc-M-t-.pdf
    • http://muicuiu.dumb1.com/5a05a03a02a06a06/Florence-amp-Tuscany-by-Christopher-Catling.pdf
    • http://muicuiu.dumb1.com/3a08a06a09a02a02/Taking-Tuscany-A-J-2-by-Renee-Riva.pdf
    • http://muicuiu.dumb1.com/3a03a08a04a02a09/Summer-in-Tuscany-by-Elizabeth-Adler.pdf
    • http://muicuiu.dumb1.com/4a06a02a08a00a06/That-Month-in-Tuscany-by-Inglath-Cooper.pdf
    • http://muicuiu.dumb1.com/4a09a07a02a03/Summer-in-Tuscany-by-Elizabeth-Adler.pdf
    • http://muicuiu.dumb1.com/7a03a01a00a09a02/My-Honorable-Highlander-Highland-Games-Through-Time-1-by-Nancy-Lee-Badger.pdf
    • http://muicuiu.dumb1.com/4a06a09a09a03/The-Killings-At-Badger-s-Drift-Chief-Inspector-Barnaby-1-by-Caroline-Graham.pdf
    • http://muicuiu.dumb1.com/6a05a06a09a05/Genie-in-Training-by-Meredith-Badger