Malicious PDF — malware analysis report

Static analysis result for SHA-256 df419e2e67396365…

MALICIOUS

PDF

18.0 KB Created: 2019-04-30 03:47:54 +01:00 Authoring application: mPDF 5.7
MD5: 5a0c213682bf7f04ba77aea9123dda28 SHA-1: 8f0cf6b09ee7ebac60ccc3130773d96aed49a2c8 SHA-256: df419e2e673963658b649435fd69e3613e89d629059390cb30063f77925cc1e2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a mass of external links, identified as a link farm, likely intended to direct users to malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample, and the document body was unreadable, but the heuristic firings and embedded URLs indicate a social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a09a04a01a03a09/Fuga-do-Campo-14-A-Dram-tica-Jornada-de-um-Prisioneiro-da-Cor-ia-do-Norte-rumo-Liberdade-no-Ocidente-by-Blaine-Harden.pdf
    • http://muicuiu.dumb1.com/3a00a04a04a05/Escape-from-Camp-14-by-Blaine-Harden.pdf
    • http://muicuiu.dumb1.com/2a05a04a06a04a05/Escape-from-Camp-14-One-Man-s-Remarkable-Odyssey-from-North-Korea-to-Freedom-In-the-West-by-Blaine-Harden.pdf
    • http://muicuiu.dumb1.com/4a05a09a09a09a05/Escape-from-Camp-14-One-Man-s-Remarkable-Odyssey-from-North-Korea-to-Freedom-in-the-West-by-Blaine-Harden.pdf
    • http://muicuiu.dumb1.com/8a00a04a03a08a03/Hal-Blaine-and-the-Wrecking-Crew-by-Hal-Blaine.pdf
    • http://muicuiu.dumb1.com/2a07a02a05a06a06/Raw-Spirit-In-Search-of-the-Perfect-Dram-by-Iain-Banks.pdf
    • http://muicuiu.dumb1.com/9a02a02a03a09a00/Ilha-de-Ar-A-liberdade-sufoca-Os-Qu4tro-Elementos-3-by-Josy-Stoque.pdf
    • http://muicuiu.dumb1.com/3a04a04a03a03/L-Assommoir-The-Dram-Shop-Les-Rougon-Macquart-7-by-mile-Zola.pdf
    • http://muicuiu.dumb1.com/7a09a05a04a08a09/La-nave-in-fuga-by-Robin-Hobb.pdf
    • http://muicuiu.dumb1.com/2a04a00a07a05a02/O-Desconhecido-do-Norte-Expresso-by-Patricia-Highsmith.pdf
    • http://muicuiu.dumb1.com/2a01a06a09a04/Diva-by-Rafael-Campo.pdf
    • http://muicuiu.dumb1.com/7a08a07a00a04a01/Campo-Santo-by-W-G-Sebald.pdf
    • http://muicuiu.dumb1.com/1a00a01a00a03a03a00/12-grados-de-latitud-norte-Antolog-a-de-Ciencia-Ficci-n-venezolana-by-Ediciones-Ubikness.pdf
    • http://muicuiu.dumb1.com/5a07a09a07a04a08/O-Apanhador-no-Campo-de-Centeio-by-J-D-Salinger.pdf
    • http://muicuiu.dumb1.com/1a02a02a05a00a00/Alex-Detail-s-Revolution-by-Darren-Campo.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a08a02/K-pfe-by-Maximilian-Harden.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a07a02a00/Rumo-s-Estrelas-by-DIVALDO-P-FRANCO.pdf
    • http://muicuiu.dumb1.com/1a00a05a06a04a09a07/Vidas-Sem-Rumo-The-Outsiders-by-S-E-Hinton.pdf
    • http://muicuiu.dumb1.com/7a04a05a07a08a07/Escape-the-Caldera-by-Verily-Harden.pdf
    • http://muicuiu.dumb1.com/1a01a04a04a09a04a06/AIDS-at-30-A-History-by-Victoria-A-Harden.pdf
    • http://muicuiu.dumb1.com/8a00a04a03a08a03/Hal-Blaine