Malicious PDF — malware analysis report

Static analysis result for SHA-256 d738ac3ba97edac7…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 04:57:39 +01:00 Authoring application: mPDF 5.7
MD5: f8d2cb1cbf847e4acee44c7c2900a0c5 SHA-1: caab4e2e8fbf1b2877a4aaba3b1e342606b0aca8 SHA-256: d738ac3ba97edac701230ff90f444709d30b5ccd0d1e63a5aab044766a5eeb3e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded links to external PDF documents, forming a link farm. This technique is often used to distribute malicious content or to manipulate search engine rankings. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a03a09a03/A-Good-Girl-The-Charlie-McClung-Mysteries-2-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a08a07a04a08/Brilliant-Disguise-The-Charlie-McClung-Mysteries-1-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/9a09a09a00a01/Criminal-Kind-The-Charlie-McClung-Mysteries-3-by-Mary-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/3a03a06a06a03a02/Matriarch-Queen-Mary-and-the-House-of-Windsor-by-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/3a06a08/The-Good-Girl-by-Mary-Kubica.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a00a00a05/The-Thief-Who-Spat-In-Luck-s-Good-Eye-Amra-Thetys-2-by-Michael-McClung.pdf
    • http://muicuiu.dumb1.com/1a03a04a01a09a03/The-Best-Corpse-for-the-Job-Lindenshaw-Mysteries-1-by-Charlie-Cochrane.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5-Midnight-for-Charlie-Bone-Charlie-Bone-and-the-Time-Twister-Charlie-Bone-and-the-Invisible-Boy-Charlie-Bone-and-the-Castle-of-Mirrors-and-Charlie-Bone-and-the-Hidden-King-by-Jenny-Nimmo.pdf
    • http://muicuiu.dumb1.com/9a07a06a00a07/The-Fox-Princess-The-Rizwan-Sabir-Mysteries-2-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/4a04a01a09a08a03/The-Anne-Stories-Anne-of-Green-Gables-1-3-5-7-8-Story-Girl-1-2-by-L-M-Montgomery.pdf
    • http://muicuiu.dumb1.com/9a08a04a08a05/Blood-Honeymoon-The-Rizwan-Sabir-Mysteries-3-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/7a09a09a02a06a01/Murder-Most-Rural-The-Rizwan-Sabir-Mysteries-5-by-Charlie-Flowers.pdf
    • http://muicuiu.dumb1.com/5a04a04a03/The-Girl-Who-Was-Taken-by-Charlie-Donlea.pdf
    • http://muicuiu.dumb1.com/1a09a05a05a02a08/Charlie-Presumed-Dead-by-Anne-Heltzel.pdf
    • http://muicuiu.dumb1.com/9a06a04a07a01a05/The-Blackmail-of-Evelynn-Faust-by-Shirley-Anne-Edwards.pdf
    • http://muicuiu.dumb1.com/2a03a04a03a02a02/Good-Grief-Charlie-Brown-Peanuts-Coronet-12-by-Charles-M-Schulz.pdf
    • http://muicuiu.dumb1.com/3a05a05a03a09a04/The-World-According-to-Tom-Hanks-The-Life-the-Obsessions-the-Good-Deeds-of-America-s-Most-Decent-Guy-by-Gavin-Edwards.pdf
    • http://muicuiu.dumb1.com/4a00a01a00a02a04/The-Incredible-Charlie-Carewe-by-Mary-Astor.pdf
    • http://muicuiu.dumb1.com/4a08a09a06a02/A-Girl-Named-Charlie-Lester-by-Carissa-Halston.pdf
    • http://muicuiu.dumb1.com/1a01a06a00a01a09a02/A-Good-Man-Gone-Mercy-Watts-Mysteries-1-by-A-W-Hartoin.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a05a06/The-Children-of-the-Red-King-Books-1-5-Midnight-for-Charlie-Bone-Charlie-Bone-and-the-Time-Twister-