Malicious PDF — malware analysis report

Static analysis result for SHA-256 defecbc09ba8b2b5…

MALICIOUS

PDF

22.3 KB Created: 2019-04-30 05:01:01 +01:00 Authoring application: mPDF 5.7
MD5: 07b88ce62dcaf5b9f86d1a9be6e6295b SHA-1: d07b7e9155511c46dca73d673c9dd478e038d2bc SHA-256: defecbc09ba8b2b509859c33e42f6414edb286917c16cc1599d338a02074ed5a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. While the document body contains garbled text, the presence of numerous links suggests a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a04a09a02a02a02/Life-on-the-Mississippi-1883-by-Mark-Twain-Life-on-the-Mississippi-1883-Is-a-Memoir-by-Mark-Twain-of-His-Days-as-a-Steamboat-Pilot-on-the-Mississippi-River-Before-the-American-Civil-War-and-Also-a-Travel-Book-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/8a04a05a01a07a06/A-Connecticut-Yankee-in-King-Arthur-s-Court-by-Mark-Twain-Fiction-Classics-Fantasy-amp-Magic-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/5a02a03a06a02a08/A-Connecticut-Yankee-in-King-Arthur-s-Court-Complete-by-Mark-Twain-Samuel-Clemens-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/3a04a04a00a07a03/The-Tragedy-of-Pudd-nhead-Wilson-by-Mark-Twain-Fiction-Classics-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/4a08a06a07a09a03/The-Devil-s-Race-Track-Mark-Twain-s-Great-Dark-Writings-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/2a00a09a03a06a05/Autobiography-of-Mark-Twain-Volume-3-The-Complete-and-Authoritative-Edition-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/5a07a06a09a05a00/Mark-Twain-s-Adventures-of-Tom-Sawyer-The-Original-Text-Edition-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/8a06a02a05a05a04/Mark-Twain-s-Struwwelpeter-Bilingual-edition-English-and-German-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a06a02a00a02a09/The-Adventures-of-Tom-Sawyer-by-Mark-Twain-Illustrated-by-Norman-Rockwell-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/1a00a07a05a03a08a06/Mark-Twain-s-the-Prince-and-the-Pauper-A-Radio-Dramatization-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a09a05a02a07a06/The-Original-Illustrated-Mark-Twain-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a01a08a04a00a03/The-Prince-and-the-Pauper---Mark-Twain-Hardcover-First-Edition-amp-Hardcover-First-Edition---University-Of-Chicago-Press-ANNOTATED-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/2a02a02a02a04a06/Mark-Twain-Speaking-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/5a04a08a04a04/The-Autobiography-of-Mark-Twain-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/8a08a09a02a08a09/Huckleberry-Finns-Abenteuer-Mark-Twains-Abenteuer-in-f-nf-B-nden-Band-2-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a09a05a01a09a03/Who-Is-Mark-Twain-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a01a09a06a02a07/Tom-Sawyer-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/9a09a05a01a09a05/How-to-Tell-a-Story-and-Other-Essays-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/3a03a05a04a04/The-Prince-and-the-Pauper-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/5a04a00a01a00a02/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://muicuiu.dumb1.com/2a00a09a03a06a05/Autobiography-of-Mark-Twain-Volume-3-The-Complete-and-Authoritative-Edition-by-M