Malicious PDF — malware analysis report

Static analysis result for SHA-256 da6b4c03ed10d3b3…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 02:44:46 +01:00 Authoring application: mPDF 5.7
MD5: 8a669fa97b3a734f6ede80455be300b8 SHA-1: d7b12fc53beb17a3a310f76efd20343e1ff48e97 SHA-256: da6b4c03ed10d3b3c1524947b6eeecd8da75bad093e28c150c36ed74ad2416df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' and the sheer volume of links to a single domain suggest a coordinated effort to direct users to potentially harmful content, possibly as a lure or to host further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a08a02a03a00a09/Team-Lucas-The-Saints-Team-1-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/2a08a02a08a03a00/Team-Tom-s-The-Saints-Team-2-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/4a01a04a06a02a05/Team-Niklas-The-Saints-Team-3-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/1a02a08a03a05a07/The-Team-Formula-A-Leadership-Tale-of-a-Team-Who-Found-Their-Way-by-Mandy-Flint.pdf
    • http://muicuiu.dumb1.com/9a05a04a08a07a00/Team-Captain-Leadership-C-L-A-S-S-Curriculum-Module-II-of-III-Team-Leadership-The-Dynamics-and-Challenges-of-Leading-Others-in-Organizations-and-Teams-by-Dr-Philip-Willenbrock.pdf
    • http://muicuiu.dumb1.com/1a09a02a04a00a09/Two-Man-Team-Team-2-by-Jet-Mykles.pdf
    • http://muicuiu.dumb1.com/2a09a04a02a09a04/Space-Team-Space-Team-1-by-Barry-J-Hutchison.pdf
    • http://muicuiu.dumb1.com/5a07a04a06a00a02/Ultimo-viene-il-leader-Perch-alcuni-team-sono-coesi-e-altri-no-Perch-alcuni-team-sono-coesi-e-altri-no-by-Simon-Sinek.pdf
    • http://muicuiu.dumb1.com/5a00a04a08a08/The-Nazi-Hunters-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazis-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazi-by-Neal-Bascomb.pdf
    • http://muicuiu.dumb1.com/3a05a05a09a08a02/The-Other-Team-by-S-B-Sheeran.pdf
    • http://muicuiu.dumb1.com/2a01a09a09a00a04/Red-Rover-Team-Red-1-by-T-Hammond.pdf
    • http://muicuiu.dumb1.com/4a06a06a02a03a09/Someone-Like-Her-K2-Team-2-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/9a01a03a06a07a05/Fr-hst-ck-amp-Brunch-by-ZS-Team.pdf
    • http://muicuiu.dumb1.com/6a07a02a07a06a00/Ogawa-and-Team-Saito-vol-04-by-Sakyo.pdf
    • http://muicuiu.dumb1.com/4a03a03a09a00a02/Crazy-for-Her-K2-Team-1-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/8a08a09a07a00a08/Deadpool-Team-Up-883-by-Skottie-Young.pdf
    • http://muicuiu.dumb1.com/2a02a05a03a01a03/The-Best-Team-Money-Can-Buy-by-Molly-Knight.pdf
    • http://muicuiu.dumb1.com/3a04a02a03a03a05/Double-Team-by-Sabrina-Paige.pdf
    • http://muicuiu.dumb1.com/3a00a04a04a02a00/Forever-s-Team-by-John-Feinstein.pdf
    • http://muicuiu.dumb1.com/3a00a02a04a06a05/Crazy-for-Her-K2-Team-1-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/5a07a04a06a00a02/Ultimo-viene-il-leader-Perch-alcuni-t