Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1e88bc219f6c482…

MALICIOUS

PDF

23.4 KB Created: 2019-04-30 08:00:26 +01:00 Authoring application: mPDF 5.7
MD5: b00604056198d95f59346bbe9c59d27e SHA-1: f73073724ed8a0cd80aed73836da1a5b5679a4c1 SHA-256: d1e88bc219f6c48223a35ff514e08206b8e83fd9547fea05f99ebac3ff7d6a11
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting the document's purpose is to distribute traffic to numerous external sites. While no scripts were extracted, the sheer volume of links points to a malicious intent, likely for SEO poisoning or redirecting users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a09a02a09a09a05/Les-5-Cercueils-de-L-Empereur-Souvenirs-Inedits-de-Philippe-de-Rohan-Chabot-Commissaire-Du-Roi-Louis-Philippe-by-Philippe-Ferdinand-Auguste-de-Rohan-Chabot-Jarnac.pdf
    • http://muicuiu.dumb1.com/5a04a07a00a01a04/Le-cauchemar-du-Pacifique-by-Jade-Chabot.pdf
    • http://muicuiu.dumb1.com/5a00a03a03a01a00/Hello-Kitty-Box-Set-Includes-Volumes-1-6-by-Jacob-Chabot.pdf
    • http://muicuiu.dumb1.com/7a04a04a06a09a06/The-Triumph-of-Melchior-Zedec-by-Jean-Nil-Chabot.pdf
    • http://muicuiu.dumb1.com/1a01a00a06a07a03a04/Understanding-Understanding-Essays-on-Cybernetics-and-Cognition-by-Heinz-von-Foerster.pdf
    • http://muicuiu.dumb1.com/1a01a09a06a01a04a05/Freud-on-Schreber-Psychoanalytic-Theory-and-the-Critical-ACT-by-C-Barry-Chabot.pdf
    • http://muicuiu.dumb1.com/7a07a03a08a04a03/Understanding-Shingles-The-Understanding-Series-by-Fernando-Cr-tte.pdf
    • http://muicuiu.dumb1.com/1a00a01a03a09a08a01/Andorra-I-L-Euro-by-Joan-Elias.pdf
    • http://muicuiu.dumb1.com/7a02a02a05a00a03/Kay-Kay-and-the-Euro-Green-Monster-Kay-Kay-2-by-Talia.pdf
    • http://muicuiu.dumb1.com/7a02a02a05a06a09/French-II---2nd-Ed-Rev-Euro-by-Pimsleur-Language-Programs.pdf
    • http://muicuiu.dumb1.com/9a03a05a04a09a04/Civilian-Power-An-Analysis-of-Euro-Mediterranean-Relations-by-Boie.pdf
    • http://muicuiu.dumb1.com/7a02a02a06a08a06/Unhappy-Union-How-the-Euro-Crisis--and-Europe---Can-Be-Fixed-by-John-Peet.pdf
    • http://muicuiu.dumb1.com/7a02a02a06a05a05/Europe-s-Unfinished-Currency-The-Political-Economics-of-the-Euro-by-Thomas-Mayer.pdf
    • http://muicuiu.dumb1.com/7a01a01a01a02a01/The-Barcelona-Process-Building-a-Euro-Mediterranean-Regional-Community-by-A-Vasconcelos.pdf
    • http://muicuiu.dumb1.com/1a01a04a00a02a06a05/Das-Euro-Desaster-Wie-deutsche-Wirtschaftspolitik-die-Eurozone-in-den-Abgrund-treibt-by-Heiner-Flassbeck.pdf
    • http://muicuiu.dumb1.com/7a02a02a06a05a03/Canada-In-Decay-Mass-Immigration-Diversity-and-the-Ethnocide-of-Euro-Canadians-by-Ricardo-Duchesne.pdf
    • http://muicuiu.dumb1.com/2a05a04a05a00a06/The-Euro-Is-Dead-Long-Live-the-Solid-A-Proposal-for-a-New-Monetary-System-for-the-Eurozone-by-Eduardo-J-Belgrano.pdf
    • http://muicuiu.dumb1.com/8a04a04a04a06a08/The-Ninety-Five-Theses-on-Christian-Liberty-and-Address-to-the-Christian-Nobility-by-Martin-Luther.pdf
    • http://muicuiu.dumb1.com/7a00a09a08a01a06/Catechism-of-Christian-Doctrine-for-Junior-Classes-and-First-Communicants-by-Brothers-of-the-Christian-Schools.pdf
    • http://muicuiu.dumb1.com/3a06a02a06a08a03/Speaking-Christian-Why-Christian-Words-Have-Lost-Their-Meaning-and-Power---And-How-They-Can-Be-Restored-by-Marcus-J-Borg.pdf
    • http://muicuiu.dumb1.com/7a07a03a08a04a03/Understanding-Shingles-The-Understanding-Series-by-Fern