Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdc72ca079f57f31…

MALICIOUS

PDF

17.6 KB Created: 2019-05-02 01:00:20 +01:00 Authoring application: mPDF 5.7
MD5: 016867203ecf8c65f378c3d87a4fe8db SHA-1: 7a50a461ed0a2555c598a9a42185e3924c6eef10 SHA-256: cdc72ca079f57f31a4a784b33bad27044d22f12ac0fa6c5491a3c4b4aa5efe01
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF_SEO_LINK_FARM heuristic indicates the document contains a large number of external links, suggesting a malicious intent to manipulate search engine results or redirect users. While the document body is heavily obfuscated, the presence of numerous URLs points towards a link-farming or redirection attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a06a02a00a04a00/History-of-Darjeeling-and-the-Sikkim-Himalaya-by-K-C-Bhanja.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a02a05a01/Notes-on-Tours-in-Darjeeling-and-Sikkim-with-Map-by-W-J-Buchanan.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a00a02a06/Darjeeling-Revisited-A-Journey-on-the-Darjeeling-Himalayan-Railway-by-Bob-Cable.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a00a03a04/The-Darjeeling-Himalayan-Railway-A-Guide-To-The-D-H-R-Darjeeling-And-Its-Tea-by-Richard-Wallace.pdf
    • http://muicuiu.dumb1.com/1a01a06a01a09a07a08/Darjeeling-A-History-of-the-World-s-Greatest-Tea-by-Jeff-Koehler.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a02a04a04/Fallen-Cicada-Unwritten-History-of-Darjeeling-Hills-by-Sanjay-Biswas-Barun-Roy.pdf
    • http://muicuiu.dumb1.com/1a08a04a09a01/The-High-Himalaya-by-Art-Wolfe.pdf
    • http://muicuiu.dumb1.com/8a09a05a03a03/Rendezvous-in-the-Himalaya-Refractions-2-by-Angela-Koenig.pdf
    • http://muicuiu.dumb1.com/1a01a03a07a04a08a00/Unter-Meistern-im-Himalaya-Autobiographie-by-Swami-Rama.pdf
    • http://muicuiu.dumb1.com/8a07a06a06a07a00/Butter-Tea-at-Sunrise-A-Year-in-the-Bhutan-Himalaya-by-Britta-Das.pdf
    • http://muicuiu.dumb1.com/1a00a01a00a00a01a04/Nepal-Nieuwe-wegen-in-de-Himalaya-by-Nick-Meynen.pdf
    • http://muicuiu.dumb1.com/1a01a04a03a03a03/A-Slender-Thread-Escaping-Disaster-in-the-Himalaya-by-Stephen-Venables.pdf
    • http://muicuiu.dumb1.com/1a00a01a07a04a06a09/Reise-in-den-Himalaya-Geschichten-f-rs-Handgep-ck-by-Alice-Gr-nfelder.pdf
    • http://muicuiu.dumb1.com/1a01a06a01a09a07a04/Darjeeling-by-T-A-Noonan.pdf
    • http://muicuiu.dumb1.com/7a09a00a00a07a03/Great-Himalaya-Trail-1-700-Kilometres-Across-the-Roof-of-the-World-by-Gerda-Pauler.pdf
    • http://muicuiu.dumb1.com/1a01a05a07a00a07/Murder-in-the-High-Himalaya-Loyalty-Tragedy-and-Escape-from-Tibet-by-Jonathan-Green.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a00a06a04/To-Sip-Darjeeling-at-Dawn-by-Donna-Pucciani.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a00a06a03/Church-Bells-and-Darjeeling-Tea-by-Zeena-Chowdhury.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a01a05a07/The-Darjeeling-Himalayan-Railway-Illustrated-for-Tourists-by-Various.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a02a04a09/Darjeeling-Ditties-and-Other-Poems-A-Souvenir-by-J-a-Keble.pdf