Malicious PDF — malware analysis report

Static analysis result for SHA-256 dbeed2beb82ab207…

MALICIOUS

PDF

19.2 KB Created: 2019-05-03 06:27:48 +01:00 Authoring application: mPDF 5.7
MD5: 32a65354305bca766e1f3afde14e1ae8 SHA-1: 973ea4e6d3efe150b0420602f812ab3cc23ef16f SHA-256: dbeed2beb82ab2070520343ed896aaaabe8b2ee0320cce97cc0f64e316591181
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a lure for further malicious activity. No scripts were extracted from this sample. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a04a05a00a09a04/The-Incurable-Electric-Literature-s-Recommended-Reading-Book-14-by-Antal-Szerb.pdf
    • http://muicuiu.dumb1.com/1a00a04a05a00a01a01/Oliver-VII-by-Antal-Szerb.pdf
    • http://muicuiu.dumb1.com/1a00a04a05a00a01a03/The-Third-Tower-Journeys-in-Italy-by-Antal-Szerb.pdf
    • http://muicuiu.dumb1.com/1a00a04a05a00a09a02/Reflections-in-the-Library-Selected-Literary-Essays-1926-1944-by-Antal-Szerb.pdf
    • http://muicuiu.dumb1.com/7a06a05a05a07/Book-Lust-Recommended-Reading-for-Every-Mood-Moment-and-Reason-by-Nancy-Pearl.pdf
    • http://muicuiu.dumb1.com/1a09a05a06a04a05/Book-Lust-to-Go-Recommended-Reading-for-Travelers-Vagabonds-and-Dreamers-by-Nancy-Pearl.pdf
    • http://muicuiu.dumb1.com/9a05a09a01a03a03/Bridge-to-Terabithia---Reading-Skills-Through-Literature-Portals-to-Reading-Series-by-Katherine-Paterson.pdf
    • http://muicuiu.dumb1.com/1a00a08a06a09a09a00/Reading-Native-American-Literature-A-Teacher-s-Guide-by-Bruce-A-Goebel.pdf
    • http://muicuiu.dumb1.com/1a00a00a08a08a08a00/Electric-Velocipede-25-Electric-Velocipe-25-by-John-Klima.pdf
    • http://muicuiu.dumb1.com/2a01a06a05a02a09/Incurable-Hearts-by-Ellie-R-Hunter.pdf
    • http://muicuiu.dumb1.com/4a07a06a03a09a09/Not-Exactly-What-I-Had-in-Mind-An-Incurable-Love-Story-by-Rosemary-Breslin.pdf
    • http://muicuiu.dumb1.com/1a01a09a01a04a04/The-Order-by-Antal-Kovacs.pdf
    • http://muicuiu.dumb1.com/6a03a03a04/I-d-Rather-Be-Reading-A-Library-of-Art-for-Book-Lovers-by-Guinevere-de-la-Mare.pdf
    • http://muicuiu.dumb1.com/4a01a04a01a03a06/Black-Water-The-Book-of-Fantastic-Literature-by-Alberto-Manguel.pdf
    • http://muicuiu.dumb1.com/4a00a08a09a05a04/The-Vintage-Book-of-Modern-Indian-Literature-by-Amit-Chaudhuri.pdf
    • http://muicuiu.dumb1.com/7a05a04a06a07a09/White-Fang-Audiobook-With-Recommended-Collection-by-Jack-London.pdf
    • http://muicuiu.dumb1.com/5a09a02a02a06a01/The-Invention-of-Literature-From-Greek-Intoxication-to-the-Latin-Book-by-Florence-Dupont.pdf
    • http://muicuiu.dumb1.com/9a06a07a07a05a03/Quest-Level-2-Reading-and-Writing-Student-Book-by-Pamela-Hartmann.pdf
    • http://muicuiu.dumb1.com/5a09a08a00a08a02/Stories-From-The-Heart-A-Reading-And-Writing-Book-For-Adults-by-Ronna-Magy.pdf
    • http://muicuiu.dumb1.com/8a04a04a08a06a09/Uncle-Tom-s-Cabin-Audiobook-With-Recommended-Collection-by-Harriet-Beecher-Stowe.pdf