Malicious PDF — malware analysis report

Static analysis result for SHA-256 d71c7c21f64856b3…

MALICIOUS

PDF

18.1 KB Created: 2019-05-03 05:25:59 +01:00 Authoring application: mPDF 5.7
MD5: 8e7295fc8ecea2971c9576e0053b7671 SHA-1: 26516c75d0cc24016687934603883c3b3cc78ef1 SHA-256: d71c7c21f64856b3172c03c779f87943bcad45172a3b98cba48f07c03edb996b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to various external websites. While the document body is unreadable, the presence of a link farm suggests a social engineering tactic to drive traffic to potentially malicious sites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a07a06a07/Fast-Girl-A-Life-Spent-Running-from-Madness-by-Suzy-Favor-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a00a02a07a02a01a05/Marvin-and-the-Meanest-Girl-by-Suzy-Kline.pdf
    • http://muicuiu.dumb1.com/3a06a06a00a04a07/Life-in-the-Fast-Lane-2nd-edition-Fast-Lane-Series-by-Michelle-McCorkle.pdf
    • http://muicuiu.dumb1.com/5a05a07a07a06a04/Clownery-In-Lieu-of-a-Life-Spent-in-Harness-by-Paul-Hunter.pdf
    • http://muicuiu.dumb1.com/9a01a02a06a09/10-10-10-A-Life-Transforming-Idea-by-Suzy-Welch.pdf
    • http://muicuiu.dumb1.com/2a03a08a02a05a00/Mortician-Diaries-The-Dead-Honest-Truth-from-a-Life-Spent-with-Death-by-June-Nadle.pdf
    • http://muicuiu.dumb1.com/1a00a09a01a04a05a03/Making-the-Big-Leap-Coach-Yourself-to-Create-the-Life-You-Really-Want-by-Suzy-Greaves.pdf
    • http://muicuiu.dumb1.com/3a07a09a00a05a02/Portrait-of-a-Girl-Running-by-J-B-Chicoine.pdf
    • http://muicuiu.dumb1.com/2a07a02a07a02a08/Running-Like-a-Girl-by-Alexandra-Heminsley.pdf
    • http://muicuiu.dumb1.com/2a03a03a03a01a07/The-Running-Girl-Kaunovalta-1-by-D-Alexander-Neill.pdf
    • http://muicuiu.dumb1.com/2a08a08a02a07a02/Sad-Girl-Sitting-on-a-Running-Board-by-Michael-McFee.pdf
    • http://muicuiu.dumb1.com/4a00a09a01a07a02/Running-Like-a-Girl-Notes-on-Learning-to-Run-by-Alexandra-Heminsley.pdf
    • http://muicuiu.dumb1.com/1a00a09a01a04a09a04/Making-the-Big-Leap-7-Steps-to-Living-a-Brave-Inspired-and-Great-Life-by-Suzy-Greaves.pdf
    • http://muicuiu.dumb1.com/3a03a07a04a04a05/The-Girl-on-the-Velvet-Swing-Sex-Murder-and-Madness-at-the-Dawn-of-the-Twentieth-Century-by-Simon-Baatz.pdf
    • http://muicuiu.dumb1.com/4a09a04a04a06/Rise-Up-and-Salute-the-Sun-The-Writings-of-Suzy-Kassem-by-Suzy-Kassem.pdf
    • http://muicuiu.dumb1.com/1a08a08a01a04a07/Come-the-Dark-a-New-Adult-Paranormal-Fantasy-Forever-Girl-Series-Book-Two-by-Rebecca-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a01a01a06a00a01/Madness-A-Bipolar-Life-by-Marya-Hornbacher.pdf
    • http://muicuiu.dumb1.com/3a09a08a07a05/Madness-A-Bipolar-Life-by-Marya-Hornbacher.pdf
    • http://muicuiu.dumb1.com/5a00a01a08a00/Fast-Trapped-Fast-Track-Trilogy-2-by-Tracy-Rozzlynn.pdf
    • http://muicuiu.dumb1.com/5a09a03a09a09/Fast-Tracked-Fast-Track-Trilogy-1-by-Tracy-Rozzlynn.pdf
    • http://muicuiu.dumb1.com/3a07a09a00a05a02/Portrait-of-a-Girl-Running-by-J-B-Chicoin