Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfa7997a90575a00…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 02:48:05 +01:00 Authoring application: mPDF 5.7
MD5: 7ff296aee63be551b585b8697c43c9ec SHA-1: 22810e3cf60c6e4b46afe419a5c3a347d661c445 SHA-256: dfa7997a90575a001d7592c7781528f17291dc1c27ec9896c27db5d87a8975ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most individual URLs were marked as confirmed benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to potentially harmful sites. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a09a08a03a03a08/Devils-Glen-Bettendorf-Tales-1-by-Matthew-Speak.pdf
    • http://muicuiu.dumb1.com/3a02a02a09a07a09/Glen-amp-Tyler-s-Erotic-Tales-Just-Married-Glen-amp-Tyler-s-Erotic-Tales-1-by-J-B-Sanders.pdf
    • http://muicuiu.dumb1.com/4a01a08a04a05a00/-devils-and-realist-1-Makai-Ouji-Devils-and-Realist-1-Devils-and-Realist-1-by-Madoka-Takadono.pdf
    • http://muicuiu.dumb1.com/5a00a06a05a09a06/Men-to-Devils-Devils-to-Men-Japanese-War-Crimes-and-Chinese-Justice-by-Barak-Kushner.pdf
    • http://muicuiu.dumb1.com/8a06a01a06a05a02/Devils-with-Wings-The-Green-Devils-Assault-on-Fort-Eben-Emael-by-Harvey-Black.pdf
    • http://muicuiu.dumb1.com/8a01a00a01a03a00/Speak-Truthfully-Speak-Your-Way-to-an-Authentic-Life-with-Awareness-Courage-and-Confidence-by-Robert-Rabbin.pdf
    • http://muicuiu.dumb1.com/1a01a07a09a05a08a07/Tales-of-Suspense-104-by-Matthew-Rosenberg.pdf
    • http://muicuiu.dumb1.com/2a09a07a08a02a07/The-Bumpkinton-Tales-Volume-One-by-Matthew-Drzymala.pdf
    • http://muicuiu.dumb1.com/1a03a01a07a01a03/A-Monstrous-Place-Tales-From-Between-1-by-Matthew-Stott.pdf
    • http://muicuiu.dumb1.com/2a09a08a02a06a01/The-Bachelor-Bumpkinton-Tales-3-by-Matthew-Drzymala.pdf
    • http://muicuiu.dumb1.com/2a05a01a02a03a01/Tales-From-the-Hand-A-Soujourns-Song-by-Matthew-Kowalski.pdf
    • http://muicuiu.dumb1.com/1a09a07a03a01a00/Glen-amp-Tyler-s-Honeymoon-Adventure-Glen-amp-Tyler-s-Adventures-1-by-J-B-Sanders.pdf
    • http://muicuiu.dumb1.com/2a05a05a01a03a03/Tigers-and-Devils-Tigers-and-Devils-1-by-Sean-Kennedy.pdf
    • http://muicuiu.dumb1.com/1a02a06a00a00a01/Devils-amp-Thieves-Devils-amp-Thieves-1-by-Jennifer-Rush.pdf
    • http://muicuiu.dumb1.com/7a01a03a09a08a03/Speak-So-You-Can-Speak-Again-The-Life-of-Zora-Neale-Hurston-by-Lucy-Hurston.pdf
    • http://muicuiu.dumb1.com/5a03a08a04a08a04/Ghosts-of-Country-Music-Tales-of-Haunted-Honky-Tonks-amp-Legendary-Spectres-by-Matthew-L-Swayne.pdf
    • http://muicuiu.dumb1.com/3a02a09a01a07a01/Glen-amp-Tyler-s-Scottish-Troubles-Glen-amp-Tyler-2-by-J-B-Sanders.pdf
    • http://muicuiu.dumb1.com/5a06a08a05a07a01/Collections-of-Fairy-Tales-The-Tales-of-Beedle-the-Bard-Grimm-s-Fairy-Tales-Andrew-Lang-s-Fairy-Books-the-Happy-Prince-and-Other-Tales-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/5a01a01a00a08a03/The-Book-of-Matthew-by-Matthew-Welton.pdf
    • http://muicuiu.dumb1.com/2a01a03a09a03a03/Of-Iron-and-Devils-by-B-H-Young.pdf
    • http://muicuiu.dumb1.com/8a01a00a01a03a00/Speak-Truthfully-Speak-Your-Way-to-an-Authentic-Life-with-Awa