Malicious PDF — malware analysis report

Static analysis result for SHA-256 df8c715732cf3cc2…

MALICIOUS

PDF

22.5 KB Created: 2019-05-02 10:36:53 +01:00 Authoring application: mPDF 5.7
MD5: 62c1854802988dd745c3dcf60a900a28 SHA-1: b568f6bc0acd30be99fcfe0eec9a216a3d9f2ccf SHA-256: df8c715732cf3cc2fbcffcd268c82007e80e46f5f1d163c828dfcb4bc4e1c2a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these specific URLs were labeled as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a00a00a02a08a04/Wildflowers-of-Cornwall-and-the-Isles-of-Scilly-by-David-Chapman.pdf
    • http://muicuiu.dumb1.com/2a00a00a02a04a00/Golden-Harvest-The-Story-Of-Daffodil-Growing-In-Cornwall-And-The-Isles-Of-Scilly-by-Andrew-Tompsett.pdf
    • http://muicuiu.dumb1.com/2a00a00a02a08a07/The-Isles-of-Scilly-New-Naturalist-103-by-Rosemary-Parslow.pdf
    • http://muicuiu.dumb1.com/2a01a07a08a02a08/Lord-of-the-Isles-Lord-of-the-Isles-1-by-David-Drake.pdf
    • http://muicuiu.dumb1.com/4a03a05a09a04a04/A-Bake-Off-in-Cornwall-A-Wedding-in-Cornwall-Book-5-by-Laura-Briggs.pdf
    • http://muicuiu.dumb1.com/1a09a06a09a09a09/A-Wedding-in-Cornwall-Cornwall-1-by-Laura-Briggs.pdf
    • http://muicuiu.dumb1.com/2a03a09a09a09a02/Mindbender-Sovereign-of-the-Seven-Isles-3-by-David-A-Wells.pdf
    • http://muicuiu.dumb1.com/2a09a00a03a02a05/Queen-of-Demons-Lord-of-the-Isles-2-by-David-Drake.pdf
    • http://muicuiu.dumb1.com/2a03a09a09a07a08/Cursed-Bones-Sovereign-of-the-Seven-Isles-5-by-David-A-Wells.pdf
    • http://muicuiu.dumb1.com/2a09a00a03a08a06/Goddess-of-the-Ice-Realm-Lord-of-the-Isles-5-by-David-Drake.pdf
    • http://muicuiu.dumb1.com/3a00a00a03a06a05/Lord-of-the-Isles-Isles-Templar-2-by-Amanda-Scott.pdf
    • http://muicuiu.dumb1.com/2a02a07a02a05a03/Lord-of-the-Isles-Men-of-the-Isles-1-by-Debbie-Mazzuca.pdf
    • http://muicuiu.dumb1.com/3a05a01a00a04a09/Cold-Water-Crossing-An-Account-of-the-Murders-at-the-Isles-of-Shoals-by-David-Faxon.pdf
    • http://muicuiu.dumb1.com/5a01a08a01a04a03/Never-Ending-Birds-Poems-by-David-Baker.pdf
    • http://muicuiu.dumb1.com/3a01a00a00a09a01/An-Appetite-for-Crime---The-Memoirs-of-Former-Detective-Superintendent-Ron-Chapman-by-Ron-Chapman.pdf
    • http://muicuiu.dumb1.com/3a04a01a08a02a01/Where-Have-All-the-Birds-Gone-Essays-on-the-Biology-and-Conservation-of-Birds-That-Migrate-to-the-American-Tropics-by-John-Terborgh.pdf
    • http://muicuiu.dumb1.com/4a04a04a09a05a04/Attracting-Birds-to-Your-Backyard-536-Ways-to-Create-a-Haven-for-Your-Favorite-Birds-A-Rodale-Organic-Gardening-Book-by-Sally-Roth.pdf
    • http://muicuiu.dumb1.com/6a00a04a09a09/The-Sibley-Guide-to-Birds-by-David-Allen-Sibley.pdf
    • http://muicuiu.dumb1.com/2a01a00a09a02a00/Handbook-of-Oregon-Birds-A-Field-Companion-to-Birds-of-Oregon-by-Hendrik-G-Herlyn.pdf
    • http://muicuiu.dumb1.com/5a06a08a06a07a01/Zeldapedia---The-Legend-of-Zelda-The-Wind-Waker-Locations-Angular-Isles-Aryll-s-Lookout-Beedle-s-Shop-Ship-Bird-s-Peak-Rock-Boating-Course-Bomb-Island-Bomb-Shop-C-C-Cold-Island-Cabana-Cafe-Bar-Chu-Jelly-Juice-Shop-Cliff-Plateau-Isles-Cres-by-Source-Wikia.pdf
    • http://muicuiu.dumb1.com/2a09a00a03a08a06/Goddess-of-the-Ice-Realm-Lo