Malicious PDF — malware analysis report

Static analysis result for SHA-256 d78b956e2262d8f1…

MALICIOUS

PDF

17.9 KB Created: 2019-05-02 01:40:15 +01:00 Authoring application: mPDF 5.7
MD5: feee3fa7e1fa7129e6ce7318307d9630 SHA-1: 97e112612b4bb9f6ecc97a5ec02ff5df60e64b80 SHA-256: d78b956e2262d8f183ac0e36d132447b451043cd3df315a46229f972fdbdc51f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for further malicious activity. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a07a08a00a04a00/Ancient-Greece-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a08a02a05/Philip-Ardagh-s-Book-Of-Howlers-Blunders-And-Random-Mistakery-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/7a05a02a05a06a06/The-Treasures-of-Ancient-Egypt-From-the-Rosetta-Stone-to-the-Tomb-of-Tutankhamun---The-Search-for-the-Riches-of-Ancient-Egypt-by-Jaromir-Malek.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a04a02/Ancient-Egyptian-Myths-amp-Legends-World-Book-Myths-amp-Legends-Series-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/5a00a02a06a09a00/First-Civilizations-Ancient-Mesopotamia-and-Ancient-Egypt-by-Robert-Chadwick.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a03a04/The-Grunts-All-at-Sea-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a08a06/Far-From-Great-Escape-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a08a02/The-Truth-About-Christmas-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a00a03a07/Your-Body-Boogers-and-All-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a09a08/Knights-And-Castles-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/5a02a09a02a05a01/Heir-of-Mystery-Unlikely-Exploits-2-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a01a02a00/William-the-Conqueror-Get-a-Life-1-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a08a03a02/The-Moomins-The-World-of-Moominvalley-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a01a02a02/Wow-Events-That-Changed-the-World-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/3a09a02a04a02/Awful-End-Eddie-Dickens-Trilogy-1-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a04a04/Trick-Eggs-and-Rubber-Chickens-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a08a02a06/Horrendous-Habits-The-Further-Adventures-of-Eddie-Dickens-2-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a08a02a04/Dubious-Deeds-The-Further-Adventures-of-Eddie-Dickens-1-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a00a02a09/The-Truth-about-Fairies-Elves-Gnomes-Goblins-amp-the-Little-People-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a08a01a01a06/Did-Dinosaurs-Really-Snore-100-and-a-half-Dinosaur-Questions-Answered-by-Philip-Ardagh.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a09a08a02/The-Truth-About-Chris