Malicious PDF — malware analysis report

Static analysis result for SHA-256 defb75114fc60108…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 00:04:50 +01:00 Authoring application: mPDF 5.7
MD5: 1991ff11f7e3a0c1beea818c279ef27e SHA-1: c3f9fce1138086c2452e8c78d4c8d0a5655f91cc SHA-256: defb75114fc6010806b305d4a407d8053a75eaf674700100a8c0ff225f1bdb02
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually marked as benign, collectively form a link farm, suggesting a tactic to drive traffic or engage in SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a06a07a09a04a04/Cold-and-Pure-and-Very-Dead-A-Karen-Pelletier-Mystery-4-by-Joanne-Dobson.pdf
    • http://muicuiu.dumb1.com/2a06a07a09a02a05/The-Raven-and-the-Nightingale-A-Karen-Pelletier-Mystery-3-by-Joanne-Dobson.pdf
    • http://muicuiu.dumb1.com/3a06a01a01a06a01/Face-of-the-Enemy-A-New-York-in-Wartime-Mystery-1-by-Joanne-Dobson.pdf
    • http://muicuiu.dumb1.com/1a03a05a07a04a02/Pure-Dead-Magic-Pure-Dead-1-by-Debi-Gliori.pdf
    • http://muicuiu.dumb1.com/3a01a05a06a08a01/Dead-and-Berried-Gray-Whale-Inn-Mystery-2-by-Karen-MacInerney.pdf
    • http://muicuiu.dumb1.com/1a07a07a07a03a06/Dead-On-Arrival-Laura-and-Gerry-Mystery-1-by-Karen-H-Vaughan.pdf
    • http://muicuiu.dumb1.com/6a03a00a06a07a06/Pelletier-Chronicles---500-Years-by-Lonnie-Pelletier.pdf
    • http://muicuiu.dumb1.com/6a03a00a06a07a07/Pelletier-Chronicles-500-Years-by-Lonnie-Pelletier.pdf
    • http://muicuiu.dumb1.com/3a01a00a09a03a04/Pure-Death-Ida-Stone-and-Sam-Fujimoto-Mystery-1-by-Liah-Penn.pdf
    • http://muicuiu.dumb1.com/1a06a01a09a09a02/The-Cold-Dead-by-E-E-Winston-IV.pdf
    • http://muicuiu.dumb1.com/2a03a06a00a06a01/Deadly-Appearances-A-Joanne-Kilbourn-Mystery-1-by-Gail-Bowen.pdf
    • http://muicuiu.dumb1.com/1a04a04a06a07a08/A-Colder-Kind-of-Death-A-Joanne-Kilbourn-Mystery-4-by-Gail-Bowen.pdf
    • http://muicuiu.dumb1.com/3a04a00a06a07a05/Dead-Speak-Cold-Case-Psychic-1-by-Pandora-Pine.pdf
    • http://muicuiu.dumb1.com/3a02a09a05a05a04/From-My-Cold-Dead-Fingers-Why-America-Needs-Guns-by-Timothy-Robert-Walters.pdf
    • http://muicuiu.dumb1.com/3a09a06a07a00a01/Ideas-Pertaining-to-a-Pure-Phenomenology-and-to-a-Phenomenological-Philosophy-First-Book-General-Introduction-to-a-Pure-Phenomenology-by-Edmund-Husserl.pdf
    • http://muicuiu.dumb1.com/2a01a02a06a01a00/Pure-Pure-1-by-Julianna-Baggott.pdf
    • http://muicuiu.dumb1.com/2a07a05a08a02a03/Adorably-Dead-A-quot-Dead-is-the-New-Fabulous-quot-Mystery-3-by-Lindsay-Maracotta.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a07a06a03/The-Day-the-World-Stopped-Cold-Curious-things-happen-in-the-dead-of-winter-by-Meghan-Hotz.pdf
    • http://muicuiu.dumb1.com/6a08a08a09a09a09/Cold-Truth-Lou-Mason-Mystery-3-by-Joel-Goldman.pdf
    • http://muicuiu.dumb1.com/3a05a00a00a04a04/A-Cold-White-Fear-A-Meg-Harris-Mystery-by-R-J-Harlick.pdf
    • http://muicuiu.dumb1.com/1a06a01a09a09a02/The-Cold-Dead-by-E-E-Wins