Malicious PDF — malware analysis report

Static analysis result for SHA-256 d217393583269dc4…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 10:34:55 +01:00 Authoring application: mPDF 5.7
MD5: 265be569f727a31115d6a7678d102251 SHA-1: d1338f9fb1ed38a1783a498cfc43154d4a866cd5 SHA-256: d217393583269dc4344f0edffe502c5c8e1a4a638dcea2a7ba30eff009bb84a9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely to redirect users to potentially harmful content or for SEO manipulation. No scripts were extracted, limiting further analysis of direct payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9472

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a07a08a07a07a03/Counting-One-s-Blessings-The-Selected-Letters-of-Queen-Elizabeth-the-Queen-Mother-by-William-Shawcross.pdf
    • http://muicuiu.dumb1.com/2a03a00a09a09a06/The-Forgotten-Queen-Warrior-Queen-1-by-Haley-Elizabeth-Garwood.pdf
    • http://muicuiu.dumb1.com/2a01a08a09a00a06/The-Vampire-Queen-Saga-Books-1-3-The-Vampire-Queen-Saga-Boxset-by-William-Stacey.pdf
    • http://muicuiu.dumb1.com/4a02a07a01a01a06/Queen-Elizabeth-s-Daughter-A-Novel-of-Elizabeth-I-by-Anne-Clinard-Barnhill.pdf
    • http://muicuiu.dumb1.com/9a06a07a05a04/Counting-Blessings-by-Amal-Alaboud.pdf
    • http://muicuiu.dumb1.com/2a03a00a04a06a07/Warrior-Queen-The-Story-of-Boudica-Celtic-Queen-by-Alan-Gold.pdf
    • http://muicuiu.dumb1.com/7a01a06a09a08a06/Censoring-Queen-Victoria-How-Two-Gentlemen-Edited-a-Queen-and-Created-an-Icon-by-Yvonne-M-Ward.pdf
    • http://muicuiu.dumb1.com/2a05a02a01a09a09/Mary-Queen-of-Scots-A-Scottish-Queen-s-Diary-France-1553-by-Kathryn-Lasky.pdf
    • http://muicuiu.dumb1.com/1a07a07a07a02/Queen-amp-Commander-Hive-Queen-Saga-1-by-Janine-A-Southard.pdf
    • http://muicuiu.dumb1.com/1a02a02a01a00a07/Twilight-of-a-Queen-The-Dark-Queen-Saga-5-by-Susan-Carroll.pdf
    • http://muicuiu.dumb1.com/2a07a02a06a07a08/The-Women-of-the-Cousins-War-The-Duchess-the-Queen-and-the-King-s-Mother-by-Philippa-Gregory.pdf
    • http://muicuiu.dumb1.com/8a06a06a02/The-Warrior-Queen-The-Hundredth-Queen-4-by-Emily-R-King.pdf
    • http://muicuiu.dumb1.com/2a05a01a01a07a08/The-Queen-and-Lord-M-Queen-Victoria-2-by-Jean-Plaidy.pdf
    • http://muicuiu.dumb1.com/7a04a01a07/The-Rogue-Queen-The-Hundredth-Queen-3-by-Emily-R-King.pdf
    • http://muicuiu.dumb1.com/1a01a00a04a03a05a02/The-History-of-Hortense-Daughter-of-Josephine-Queen-of-Holland-Mother-of-Napoleon-III-by-John-S-C-Abbott.pdf
    • http://muicuiu.dumb1.com/4a02a05a06a09a08/The-Queen-A-Biography-of-Elizabeth-II-by-Ben-Pimlott.pdf
    • http://muicuiu.dumb1.com/3a03a09a02a02a07/All-the-Queen-s-Men-The-World-of-Elizabeth-I-by-Peter-Brimacombe.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a00a02/The-Hollow-Queen-Symphony-of-Ages-8-by-Elizabeth-Haydon.pdf
    • http://muicuiu.dumb1.com/1a03a05a03a07a01/The-Summer-Queen-Eleanor-of-Aquitaine-1-by-Elizabeth-Chadwick.pdf
    • http://muicuiu.dumb1.com/3a04a00a01a04a07/Elizabeth-of-York-The-Forgotten-Tudor-Queen-by-Amy-Licence.pdf
    • http://muicuiu.dumb1.com/7a01a06a09a08a06/Censoring-Queen-Victoria-How-Two-Gentlemen-Edited-a-Queen-