Malicious PDF — malware analysis report

Static analysis result for SHA-256 df84a35fcc262844…

MALICIOUS

PDF

23.9 KB Created: 2019-04-30 07:46:21 +01:00 Authoring application: mPDF 5.7
MD5: e31422c147a533a205ade011f306616f SHA-1: 26eb4103cca7d24deee83ea83e166304e4bd1cad SHA-256: df84a35fcc26284415d7e097965bb055071687b524b9d5785f7dd3ec9b3edb95
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is heavily obfuscated, the presence of numerous links suggests a lure to external content, potentially for SEO manipulation or to host further malicious payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a04a09a04a01a09/The-Year-of-Reading-Dangerously-How-Fifty-Great-Books-Saved-My-Life-by-Andy-Miller.pdf
    • http://muicuiu.dumb1.com/3a05a04a08a00a04/The-Year-of-Reading-Dangerously-How-Fifty-Great-Books-Saved-My-Life-by-Andy-Miller.pdf
    • http://muicuiu.dumb1.com/1a00a02a06a00a03/Reading-By-Moonlight-How-Books-Saved-A-Life-by-Brenda-Walker.pdf
    • http://muicuiu.dumb1.com/1a09a05a06a04a08/So-Many-Books-So-Little-Time-A-Year-of-Passionate-Reading-by-Sara-Nelson.pdf
    • http://muicuiu.dumb1.com/1a07a02a01/My-Kitchen-Year-136-Recipes-That-Saved-My-Life-by-Ruth-Reichl.pdf
    • http://muicuiu.dumb1.com/4a07a05a02a02a09/Double-Life-The-Story-of-a-Fifty-Year-Marriage-by-Alan-Shayne.pdf
    • http://muicuiu.dumb1.com/3a05a06a09a06a07/Honey-for-a-Woman-s-Heart-Growing-Your-World-through-Reading-Great-Books-by-Gladys-M-Hunt.pdf
    • http://muicuiu.dumb1.com/1a09a03a02a07a00/Ruined-By-Reading-A-Life-in-Books-by-Lynne-Sharon-Schwartz.pdf
    • http://muicuiu.dumb1.com/9/The-War-that-Saved-My-Life-The-War-That-Saved-My-Life-1-by-Kimberly-Brubaker-Bradley.pdf
    • http://muicuiu.dumb1.com/2a09a07a09a06a04/Built-of-Books-How-Reading-Defined-the-Life-of-Oscar-Wilde-by-Thomas-Wright.pdf
    • http://muicuiu.dumb1.com/2a01a04a05a09a06/The-Year-of-Loving-Dangerously-by-Eloisa-James.pdf
    • http://muicuiu.dumb1.com/2a03a01a07a02/The-Life-of-the-Mind-in-America-From-the-Revolution-to-the-Civil-War-Books-One-Through-Three-by-Perry-Miller.pdf
    • http://muicuiu.dumb1.com/9a09a04a00a01a02/A-Year-of-Writing-Dangerously-365-Days-of-Inspiration-and-Encouragement-by-Barbara-Abercrombie.pdf
    • http://muicuiu.dumb1.com/2a06a08a08a02a02/The-Year-of-Eating-Dangerously-A-Global-Adventure-in-Search-of-Culinary-Extremes-by-Tom-Parker-Bowles.pdf
    • http://muicuiu.dumb1.com/8a09a01a04a08a09/Hugo-Von-Hofmannsthal-s-Der-Schwierige-a-Fifty-Year-Theater-History-Hugo-Von-Hofmannsthal-s-Der-Schwierige-a-Fifty-Year-Theater-History-by-Douglas-A-Joyce.pdf
    • http://muicuiu.dumb1.com/1a01a02a09a00a03a05/Fifty-Fifty-A-Dating-Guide-for-Suddenly-Single-Fifty-Somethings-by-Debra-Bellmont.pdf
    • http://muicuiu.dumb1.com/1a01a01a07a09a08a02/Boris-Akunin-Books-2017-Checklist-Reading-Order-of-An-Erast-Fandorin-Mystery-Series-and-List-of-All-Boris-Akunin-Books-by-Diamond-Books.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a00a09a07/Fifty-Shades-Trilogy-Fifty-Shades-of-Grey-Fifty-Shades-Darker-Fifty-Shades-Freed-3-volume-a-review-by-Nick-Walton.pdf
    • http://muicuiu.dumb1.com/1a07a03a08a08a05/The-Fifty-Year-Sword-by-Mark-Z-Danielewski.pdf
    • http://muicuiu.dumb1.com/8a07a09a04/I-d-Rather-Be-Reading-The-Delights-and-Dilemmas-of-the-Reading-Life-by-Anne-Bogel.pdf
    • http://muicuiu.dumb1.com/3a05a06a09a06a07/Honey-for-a-Woman-s-Heart-Growing-Your-World-through-Reading-Gr