Malicious PDF — malware analysis report

Static analysis result for SHA-256 d42b4a0843cbc774…

MALICIOUS

PDF

14.6 KB Created: 2019-05-07 03:23:52 +01:00 Authoring application: mPDF 5.7
MD5: 7d8e7f10cd33333410e879d7757778f5 SHA-1: 530f989d7b5e3636a3e7e40e56ba1255b7a3ee61 SHA-256: d42b4a0843cbc7744ae0d800f7be2dfbaac7ef7ff0585ca05e0673b97581306f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. While the specific intent of these links is unclear due to their benign reputation, the overall structure and heuristic firings suggest a malicious document designed to lure users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a01a07a04a09a01/The-Curse-Defiers-The-Curse-Keepers-3-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/4a01a01a01a06a03/The-Curse-Breakers-The-Curse-Keepers-2-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a08a00a06a07a03/The-Curse-Breakers-The-Curse-Keepers-2-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/4a06a01a02a04a06/The-Curse-Keepers-Collection-Curse-Keepers-1-3-5-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a09a08a08a00a05/The-Curse-Keepers-The-Curse-Keepers-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a00a09a07a05a03/Here-On-the-Otherside-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/1a04a08a09a01a00/There-On-the-Otherside-2-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/1a03a05a04a05a09/Here-On-the-Otherside-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/8a06a07a00a05a08/Until-You-Bachelor-Brotherhood-2-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a01a01a03a03a08/After-Math-Off-the-Subject-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/8a04a09a03a02/Redemption-The-Chosen-4-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/3a03a05a00a03a07/After-Math-Off-the-Subject-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/1a04a06a08a04a02/The-Gambler-The-Wedding-Pact-3-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/3a09a00a09a06a02/The-Player-The-Wedding-Pact-2-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/3a05a03a09a03a01/The-Substitute-The-Wedding-Pact-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/3a05a09a09a09a07/Picking-Up-the-Pieces-Rose-Gardner-Mystery-5-5-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/1a03a04a05a06a07/Thirty-and-a-Half-Excuses-Rose-Gardner-Mystery-3-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/1a03a04a06a04a02/Thirty-One-and-a-Half-Regrets-Rose-Gardner-Mystery-4-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/3a03a08a01a05a04/Chosen-The-Chosen-1-by-Denise-Grover-Swank.pdf
    • http://muicuiu.dumb1.com/2a03a04a03a09a09/Curse-of-Dragons-Sera-s-Curse-2-by-Clara-Hartley.pdf
    • http://muicuiu.dumb1.com/8a04a09a03a02/Redemption-The-Chosen-4-