Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4489fb5a69e00fd…

MALICIOUS

PDF

23.0 KB Created: 2019-04-30 02:17:13 +01:00 Authoring application: mPDF 5.7
MD5: dc2d6459fa73267e87b93a8874a8e104 SHA-1: edcbad4cd1ad8bc84a7a3b90ba5ea9d0eee493bf SHA-256: d4489fb5a69e00fd94534980ba19f72762df7c53cb5b42bdbd0f64f9c441032e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, forming a link farm. The primary heuristic indicates a "PDF_SEO_LINK_FARM" with 29 links, suggesting a tactic to drive traffic to external sites. The document body contains numerous URLs pointing to PDF files, reinforcing the link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a08a06a09a09a04/Alfred-Hitchcock-s-Daring-Detectives-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/3a08a01a08a00a07/Alfred-Hitchcock-Presents-Stories-to-Stay-Awake-By-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/8a09a09a08a07a08/Alfred-Hitchcock-Macguffin-Die-Drei-Der-Karpatenhund-Alfred-Hitchcock-Presents-Das-Fenster-Zum-Hof-Das-Gespensterschloss-Psycho-II-Hitchcockfilm-Mel-Brooks-Hohenkoller-Psycho-IV---The-Beginning-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a00a08a07a00a00a04/Alfred-Hitchcock-Presents-A-Month-Of-Mystery-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/6a02a05a08a05a04/Alfred-Hitchcock-Presents-Stories-Not-for-the-Nervous-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/3a02a07a05a00a01/Alfred-Hitchcock-s-Spellbinders-in-Suspense-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/1a00a08a06a09a02a06/Who-Was-Alfred-Hitchcock-by-Pam-Pollack.pdf
    • http://muicuiu.dumb1.com/1a00a08a07a00a00a00/Alfred-Hitchcock-Interviews-by-Sidney-Gottlieb.pdf
    • http://muicuiu.dumb1.com/2a04a05a01a09a07/The-Mystery-of-the-Invisible-Dog-Alfred-Hitchcock-and-The-Three-Investigators-23-by-M-V-Carey.pdf
    • http://muicuiu.dumb1.com/5a03a03a03a09a09/Alfred-Hitchcock-Presents-Fear-and-Trembling-by-Henry-S-Whitehead.pdf
    • http://muicuiu.dumb1.com/8a09a06a04a05a09/The-Mystery-of-the-Magic-Circle-Alfred-Hitchcock-and-The-Three-Investigators-27-by-M-V-Carey.pdf
    • http://muicuiu.dumb1.com/3a05a08a00a05a02/The-Best-of-Mystery-63-Short-Stories-By-the-Master-of-Suspense-by-Alfred-Hitchcock.pdf
    • http://muicuiu.dumb1.com/1a08a02a04a08a04/Alfred-Hitchcock-A-Life-in-Darkness-and-Light-by-Patrick-McGilligan.pdf
    • http://muicuiu.dumb1.com/4a02a06a05a09a09/The-Dark-Side-of-Genius-The-Life-of-Alfred-Hitchcock-by-Donald-Spoto.pdf
    • http://muicuiu.dumb1.com/5a07a08a04a00a09/The-Mystery-of-the-Deadly-Double-Alfred-Hitchcock-and-The-Three-Investigators-28-by-William-Arden.pdf
    • http://muicuiu.dumb1.com/2a03a07a03a06a04/The-Mystery-of-the-Green-Ghost-Alfred-Hitchcock-and-The-Three-Investigators-4-by-Robert-Arthur.pdf
    • http://muicuiu.dumb1.com/6a02a05a08a05a06/The-Mystery-of-the-Silver-Spider-Alfred-Hitchcock-and-The-Three-Investigators-8-by-Robert-Arthur.pdf
    • http://muicuiu.dumb1.com/1a00a08a06a09a09a05/The-Art-of-Alfred-Hitchcock-Fifty-Years-of-His-Motion-Pictures-by-Donald-Spoto.pdf
    • http://muicuiu.dumb1.com/1a00a08a06a09a02a02/Spellbound-by-Beauty-Alfred-Hitchcock-and-His-Leading-Ladies-by-Donald-Spoto.pdf
    • http://muicuiu.dumb1.com/2a03a01a09a08a00/The-Mystery-of-the-Coughing-Dragon-Alfred-Hitchcock-and-The-Three-Investigators-14-by-Nick-West.pdf
    • http://muicuiu.dumb1.com/1a00a08a07a00a00a00/Alfred-Hitchcock-Interviews-by-Sidney-Go