Malicious PDF — malware analysis report

Static analysis result for SHA-256 cbd2bb6bfdeadd1d…

MALICIOUS

PDF

18.0 KB Created: 2019-04-30 04:01:36 +01:00 Authoring application: mPDF 5.7
MD5: 4988a694e81c4b2c679fa6438a4f3253 SHA-1: 361d309db04c9c824c9ed755d6bcd1050e29be8a SHA-256: cbd2bb6bfdeadd1d9c3c625145ab1af7fce4203ad690cb86ae2898a1c7d56892
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm, potentially to host further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a01a02a07a09a06/Retrieving-Michigan-s-Buried-Past-The-Archaeology-of-the-Great-Lakes-State-by-John-R-Halsey.pdf
    • http://muicuiu.dumb1.com/8a00a01a05a00a00/The-Occasions-by-Eugenio-Montale.pdf
    • http://muicuiu.dumb1.com/5a05a09a05/Saints-for-All-Occasions-by-J-Courtney-Sullivan.pdf
    • http://muicuiu.dumb1.com/1a01a02a09a09a06a08/Cupcakes-amp-Cookies-Decorations-for-All-Occasions-by-Frances-McNaughton.pdf
    • http://muicuiu.dumb1.com/3a06a06a02a03a08/Near-Occasions-John-Paul-2-High-Book-5-by-Christian-M-Frank.pdf
    • http://muicuiu.dumb1.com/5a03a09a07a00a07/A-Guide-to-Elegance-For-Every-Woman-Who-Wants-to-Be-Well-and-Properly-Dressed-on-All-Occasions-by-Genevi-ve-Antoine-Dariaux.pdf
    • http://muicuiu.dumb1.com/9a09a05a06a04a09/The-Epicurious-Cookbook-More-Than-250-of-Our-Best-Loved-Four-Fork-Recipes-for-Weeknights-Weekends-amp-Special-Occasions-by-Tanya-Steel.pdf
    • http://muicuiu.dumb1.com/3a06a08a01a03a00/Putting-God-Back-in-the-Holidays-Celebrate-Christmas-Thanksgiving-Easter-Birthdays-and-12-Other-Special-Occasions-with-Purpose-by-Bill-Thrasher.pdf
    • http://muicuiu.dumb1.com/6a06a03a04a00a08/Elsa-Lanchester-Herself-by-Elsa-Lanchester.pdf
    • http://muicuiu.dumb1.com/2a04a00a09a05a02/The-Sun-Egg-by-Elsa-Beskow.pdf
    • http://muicuiu.dumb1.com/7a04a01a00a05a02/The-Whisperer-by-Elsa-Winckler.pdf
    • http://muicuiu.dumb1.com/6a02a06a02a09a03/Mes-comptines-by-Elsa-Fouquier.pdf
    • http://muicuiu.dumb1.com/7a04a01a00a05a01/Love-In-Writing-by-Elsa-Winckler.pdf
    • http://muicuiu.dumb1.com/2a07a09a09a06a09/Children-of-the-Forest-by-Elsa-Beskow.pdf
    • http://muicuiu.dumb1.com/7a04a01a01a01a03/Touched-to-the-Soul-by-Elsa-Winckler.pdf
    • http://muicuiu.dumb1.com/2a08a03a06a06a04/The-Puppy-Trap-by-Elsa-Watson.pdf
    • http://muicuiu.dumb1.com/1a06a06a04a05a01/The-Olive-Tree-by-Elsa-Marston.pdf
    • http://muicuiu.dumb1.com/1a06a09a08a09a02/The-Flowers-Festival-by-Elsa-Beskow.pdf
    • http://muicuiu.dumb1.com/8a02a06a03a06a00/The-Inspector-of-Ruins-by-Elsa-Triolet.pdf
    • http://muicuiu.dumb1.com/6a07a04a04a03a00/Elsa-The-Secret-Heritage-1-by-Allison-Bruning.pdf
    • http://muicuiu.dumb1.com/9a09a05a06a04a09/The-Epicurious-Cookbook