Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca8b8a7f73553191…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 04:30:47 +01:00 Authoring application: mPDF 5.7
MD5: 71940813fb5ac9ad3a8649d71c37a8da SHA-1: f3694fbac1a40a9eb71c072e65276137f5daa573 SHA-256: ca8b8a7f735531912d98a637cbdd4591a99163596ed9848e166c83810eb85dca
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While most of the linked URLs appear benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to direct users to phishing or malware-hosting sites. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dum
    • http://muicuiu.dumb1.com/4a07a06a04a02a02/Fireweed-A-Political-Autobiography-by-Gerda-Lerner.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a07a04a06/The-Feminist-Thought-of-Sarah-Grimke-by-Gerda-Lerner.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a08a00a01/The-Majority-Finds-Its-Past-Placing-Women-in-History-by-Gerda-Lerner.pdf
    • http://muicuiu.dumb1.com/9a02a03a07a03a06/Das-Prinzip-Gerda-Gerda-Buddenbrook-ALS-Bedeutungsvolle-Leerstelle-Und-Transitorische-Figur-in-Thomas-Manns-Buddenbrooks-by-Martin-Andiel.pdf
    • http://muicuiu.dumb1.com/5a05a07a02a07a02/A-Theory-of-Creation-A-Review-of-Vestiges-of-the-Natural-History-of-Creation-by-Francis-Bowen.pdf
    • http://muicuiu.dumb1.com/5a00a06a03a02a01/The-Father-of-All-The-de-la-Guerra-Family-Power-and-Patriarchy-in-Mexican-California-by-Louise-Pubols.pdf
    • http://muicuiu.dumb1.com/1a01a03a08a00a05a08/Fuchsias-by-Gerda-Manthey.pdf
    • http://muicuiu.dumb1.com/5a01a06a02a05a01/Icecream-by-Gerda-Dendooven.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a07a04a00/The-Pig-Society-by-Gerda-Koontz.pdf
    • http://muicuiu.dumb1.com/3a09a02a02a05a08/Buddhism-After-Patriarchy-A-Feminist-History-Analysis-and-Reconstruction-of-Buddhism-by-Rita-M-Gross.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a05a01a05/Gerda-Taro-by-Jane-Rogoyska.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a06a06a05/Gerda-The-Goose-by-Hiawyn-Oram.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a05a02a03/Saving-Gerda-by-Lilian-Darcy.pdf
    • http://muicuiu.dumb1.com/6a03a03a07a00a08/Against-the-Madness-of-Manu-B-R-Ambedkar-s-Writings-on-Brahmanical-Patriarchy-by-B-R-Ambedkar.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a05a02a05/Out-of-the-Shadows-A-Life-of-Gerda-Taro-by-Fran-ois-Maspero.pdf
    • http://muicuiu.dumb1.com/4a02a02a08a03a08/The-Hours-After-Letters-of-Love-and-Longing-in-War-s-Aftermath-by-Gerda-Weissmann-Klein.pdf
    • http://muicuiu.dumb1.com/1a01a03a01a07a02a07/Weihnachten-zart-herb-Geschichten-und-Gedichte-by-Gerda-Greschke-Begemann.pdf
    • http://muicuiu.dumb1.com/7a09a00a00a07a03/Great-Himalaya-Trail-1-700-Kilometres-Across-the-Roof-of-the-World-by-Gerda-Pauler.pdf
    • http://muicuiu.dumb1.com/3a01a00a03a05a05/All-or-Nothing-by-Rose-Lerner.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a00/Mean-Free-Path-by-Ben-Lerner.pdf