Malicious PDF — malware analysis report

Static analysis result for SHA-256 d30677bb45af1ba3…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 06:37:05 +01:00 Authoring application: mPDF 5.7
MD5: 95b22ddf422b9dd4dff5e82d1ab9d0c1 SHA-1: 07f377c25e38f88addba7081996c8b0d835d7fd3 SHA-256: d30677bb45af1ba3f2eba2e69f53b84e3ad89179d98c8177f843fe492883f3ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm, likely to host further malicious content or to engage in deceptive practices.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a05a06a09a00a09/Legends-Legacies-Destiny-Legend-of-the-White-Dragon-1-3-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/1a05a07a04a07a07/Legacies-Legend-of-the-White-Dragon-2-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/4a01a05a05a08/Dragon-of-Legend-Destiny-Fantasy-Dragon-Adventure-by-Angelika-Meyer.pdf
    • http://muicuiu.dumb1.com/4a04a06a04a03a00/A-Turn-Of-Curses-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/4a05a03a08a05a06/At-The-Waters-Edge-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/2a09a09a04a06a00/A-Dragon-s-Destiny-White-Horse-Clan-2-by-Lynn-Stark.pdf
    • http://muicuiu.dumb1.com/3a02a06a07a00a02/Starfire-Angels-Dark-Angel-Chronicles-1-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/3a07a03a01a08a07/Dark-Angel-Chronicles-Starfire-Angels-1-4-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/1a00a09a09a08a02/The-Pygmy-Dragon-Shapeshifter-Dragon-Legends-1-by-Marc-Secchia.pdf
    • http://muicuiu.dumb1.com/8a02a01a01a01/The-Dragon-Token-Dragon-Star-2-by-Melanie-Rawn.pdf
    • http://muicuiu.dumb1.com/3a08a09a07a00a08/The-Dragon-Token-Dragon-Star-2-by-Melanie-Rawn.pdf
    • http://muicuiu.dumb1.com/3a08a00a09a00a05/Twin-Dragon-s-Destiny-Dragon-Lords-of-Valdier-11-by-S-E-Smith.pdf
    • http://muicuiu.dumb1.com/4a04a00a07a08a02/A-Dream-of-Ebony-and-White-A-Retelling-of-Snow-White-Beyond-the-Four-Kingdoms-Book-4-by-Melanie-Cellier.pdf
    • http://muicuiu.dumb1.com/1a03a04a09a00a05/Starfire-Angels-Starfire-Angels-Dark-Angel-Chronicles-1-by-Melanie-Nilles.pdf
    • http://muicuiu.dumb1.com/4a07a07a00a08a04/Second-Acts-Presidential-Lives-and-Legacies-After-the-White-House-by-Mark-K-Updegrove.pdf
    • http://muicuiu.dumb1.com/1a00a00a06a02a09/Saving-a-Legend-Kavanagh-Legends-2-by-Sarah-Robinson.pdf
    • http://muicuiu.dumb1.com/5a07a09a00a04/Breaking-a-Legend-Kavanagh-Legends-1-by-Sarah-Robinson.pdf
    • http://muicuiu.dumb1.com/4a00a09a02a07/The-Legacies-Lorien-Legacies-The-Lost-Files-1-3-by-Pittacus-Lore.pdf
    • http://muicuiu.dumb1.com/8a00a09a09a01/The-Star-Scroll-Dragon-Prince-2-by-Melanie-Rawn.pdf
    • http://muicuiu.dumb1.com/4a00a08a09a01/Dragon-Prince-Dragon-Prince-1-by-Melanie-Rawn.pdf
    • http://muicuiu.dumb1.com/3a08a00a09a00a05/Twin-Dragon-s-Destiny-Dragon-Lords-of-Valdier-11-by-S-E-S