Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1cfbff38e21c767…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 02:34:26 +01:00 Authoring application: mPDF 5.7
MD5: 824570ccb3e756252898eeacc78785df SHA-1: 1aa429c4cbb4567f7e795054bcd818e8174275bb SHA-256: d1cfbff38e21c76794914696b7a4712442848bf0aefdf88b60e5db58a0002de3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the extracted URLs themselves are confirmed benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a01a08a01a07a08/The-Wedding-Day-Mystery-Nancy-Drew-136-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/7a03a09a09a08/Where-s-Nancy-Nancy-Drew-Girl-Detective-Super-Mystery-1-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/2a06a09a09a05a01/The-Bungalow-Mystery-Nancy-Drew-3-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/1a08a00a07a00a04/The-Bungalow-Mystery-Nancy-Drew-3-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/4a00a03a03a02a05/The-Bungalow-Mystery-Nancy-Drew-3-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a04a07a00a02/Mystery-of-Crocodile-Island-Nancy-Drew-Mystery-Stories-55-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/1a08a00a09a05a08/The-Scarlet-Slipper-Mystery-Nancy-Drew-Mystery-Stories-32-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a04a09a04a07/Mystery-of-the-Ivory-Charm-Nancy-Drew-Mystery-Stories-13-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a02a09a09a09/Mystery-of-the-Tolling-Bell-Nancy-Drew-Mystery-Stories-23-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a00a04a01a00/The-Mystery-at-Lilac-Inn-Nancy-Drew-Mystery-Stories-4-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a03a05a09a09/The-Mystery-at-the-Moss-covered-Mansion-Nancy-Drew-Mystery-Stories-18-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/2a01a08a02a01a05/The-Mystery-of-the-Brass-Bound-Trunk-Nancy-Drew-Mystery-Stories-17-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/7a02a08a09a03a04/The-Greek-Symbol-Mystery-Nancy-Drew-60-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/2a01a08a02a00a08/The-Missing-Horse-Mystery-Nancy-Drew-145-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a00a08a06a08/The-Flying-Saucer-Mystery-Nancy-Drew-58-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/1a00a05a09a03a09a06/The-Mystery-of-Misty-Canyon-Nancy-Drew-86-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a00a02a07a09a04/The-Music-Festival-Mystery-Nancy-Drew-157-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/3a01a05a03a04a08/The-Secret-of-the-Old-Clock-Nancy-Drew-Mystery-Stories-1-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/4a06a01a04a03a09/The-Triple-Hoax-Nancy-Drew-Mystery-Stories-57-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/2a04a04a02a05a05/Mystery-of-the-Midnight-Rider-Nancy-Drew-Diaries-3-by-Carolyn-Keene.pdf
    • http://muicuiu.dumb1.com/8a03a05a09a09/The-Mystery-at-the-Moss-covered-Mansion-Nancy-Drew-Mystery-Stories-18-by-Carolyn-Keene