Malicious PDF — malware analysis report

Static analysis result for SHA-256 d900d2ed7056f2d7…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 05:17:47 +01:00 Authoring application: mPDF 5.7
MD5: 0a0628628adf715ffb5de4fb72748ea3 SHA-1: 58becc850b18d646fe80aee83ba73c6bd5395e7f SHA-256: d900d2ed7056f2d7fc29b9812e38b30ef6e2a76de3673736e0c4e3fabd8a4eae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to direct users to malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the specific URLs appear benign, the overall structure and heuristic firing suggest an attempt to distribute or redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a06a08a07a02a06/Not-a-Silent-Night-Mary-Looks-Back-to-Bethlehem-by-Adam-Hamilton.pdf
    • http://muicuiu.dumb1.com/9a05a04a08a05a05/Silent-Night-The-Story-of-how-the-Carol-Silent-Night-Originated-by-Hanno-Schilf.pdf
    • http://muicuiu.dumb1.com/1a03a07a06a07a07/Silent-Night-2-Silent-Night-2-Fear-Street-Super-Chiller-5-by-R-L-Stine.pdf
    • http://muicuiu.dumb1.com/3a07a04a00a00a06/Silent-Night-Unexpected-Night-by-Ella-Jade.pdf
    • http://muicuiu.dumb1.com/2a07a01a00a02a09/Silent-Night-Violent-Night-by-Carol-Verburg.pdf
    • http://muicuiu.dumb1.com/9a01a08a07a00a04/The-Mary-Poppins-Omnibus-Mary-Poppins-Mary-Poppins-Comes-Back-Mary-Poppins-in-Cherry-Tree-Lane-by-P-L-Travers.pdf
    • http://muicuiu.dumb1.com/3a06a06a02a04a01/The-Call-The-Life-and-Message-of-the-Apostle-Paul-by-Adam-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a02a06a03a05a03/Beyond-Belief-Finding-the-Strength-to-Come-Back-by-Josh-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a00a00a00a04a02a00/24-Hours-That-Changed-the-World-4-Jesus-Barabbas-and-Pilate-by-Adam-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a00a00a03a08a00a01/Don-t-Look-Back-Lori-Turner-Book-2-by-Adam-Nicholls.pdf
    • http://muicuiu.dumb1.com/4a00a05a00a00a00/The-Empire-Strikes-Back---So-You-Want-to-Be-a-Jedi-by-Adam-Gidwitz.pdf
    • http://muicuiu.dumb1.com/8a04a02a03a04a04/Silent-Night-Spencer-41-5-by-Robert-B-Parker.pdf
    • http://muicuiu.dumb1.com/2a02a06a03a04a09/Soul-Surfer-A-True-Story-of-Faith-Family-and-Fighting-to-Get-Back-on-the-Board-by-Bethany-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a08a02a00a04a06/Silent-as-the-Grave-Guild-of-Truth-1-by-Mary-K-Norris.pdf
    • http://muicuiu.dumb1.com/2a06a06a02a07a00/Silent-Night-Lady-Julia-Grey-5-5-by-Deanna-Raybourn.pdf
    • http://muicuiu.dumb1.com/4a07a00a02a03/The-Naked-God-Night-s-Dawn-3-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/3a07a08a09a08/The-Reality-Dysfunction-Night-s-Dawn-1-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/4a01a03a09/A-Night-Without-Stars-Commonwealth-Universe-7-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/2a01a09a06a09a03/The-Reality-Dysfunction-Night-s-Dawn-1-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/5a00a04a05a08a07/Night-Without-Stars-Chronicle-of-the-Fallers-Book-2-by-Peter-F-Hamilton.pdf
    • http://muicuiu.dumb1.com/1a02a06a03a0