Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfcef800f27adfc5…

MALICIOUS

PDF

23.8 KB Created: 2019-04-30 04:30:01 +01:00 Authoring application: mPDF 5.7
MD5: 11e3a40ac4aa84def2fba566645cbc97 SHA-1: 9d29db3a7789d3520920baeced0cf52abcf5dfc9 SHA-256: dfcef800f27adfc56d90f0ffb509ab6533f954eb24071a958840b161bbfa4160
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or as a lure for further malicious activity. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a09a07a05a02a07/India-2020-A-Vision-For-India-in-the-21st-Century-by-A-P-J-Abdul-Kalam.pdf
    • http://muicuiu.dumb1.com/6a06a08a03a09a05/The-Elephant-the-Tiger-and-the-Cell-Phone-Reflections-on-India-the-Emerging-21st-Century-Power-by-Shashi-Tharoor.pdf
    • http://muicuiu.dumb1.com/3a04a02a05a06/Wings-of-Fire-An-Autobiography-by-A-P-J-Abdul-Kalam.pdf
    • http://muicuiu.dumb1.com/9a06a05a03a07a07/Future-Track-India-Blue-Print-for-a-Dynamic-India-by-Kartik-H-.pdf
    • http://muicuiu.dumb1.com/6a00a07a04a02a06/A-letter-to-the-Right-Honorable-the-Earl-of-Buckinghamshire-president-of-the-Board-of-Commissioners-for-the-Affairs-of-India-on-the-subject-of-an-open-trade-to-India-by-Fabius.pdf
    • http://muicuiu.dumb1.com/1a00a01a09a02a07a08/Roget-s-21st-Century-Thesaurus-21st-Century-Reference-by-Barbara-Ann-Kipfer.pdf
    • http://muicuiu.dumb1.com/8a04a09a09a04a01/Six-Acres-and-a-Third-The-Classic-Nineteenth-Century-Novel-about-Colonial-India-by-Fakir-Mohan-Senapati.pdf
    • http://muicuiu.dumb1.com/4a08a09a04a01a09/A-History-of-India-vol-1-From-Origins-to-1300-A-History-of-India-1-by-Romila-Thapar.pdf
    • http://muicuiu.dumb1.com/1a05a07a01a00a06/Dutch-East-India-Company-Shipbuilding-The-Archaeological-Study-of-Batavia-and-Other-Seventeenth-Century-VOC-Ships-by-Wendy-van-Duivenvoorde.pdf
    • http://muicuiu.dumb1.com/8a01a00a00a02a06/International-Congress-on-Renewable-Energy-2005-January-20-22-2005-Hotel-Le-Meridien-Pune-India-Ensuring-Energy-Security-and-Sustainable-Rural-Development--Globally-Conference-Proceeding-by-Solar-Energy-Society-of-India.pdf
    • http://muicuiu.dumb1.com/3a06a07a04a02a07/Post-Modern-Pilgrims-First-Century-Passion-for-the-21st-Century-World-by-Leonard-Sweet.pdf
    • http://muicuiu.dumb1.com/9a08a06a00a07a04/The-Political-Mind-Why-You-Can-t-Understand-21st-Century-American-Politics-with-an-18th-Century-Brain-by-George-Lakoff.pdf
    • http://muicuiu.dumb1.com/2a00a09a06a02a03/Dirt-HDU-2-by-India-Lee.pdf
    • http://muicuiu.dumb1.com/5a09a05a09a01a02/Gangstress-3-by-India.pdf
    • http://muicuiu.dumb1.com/5a09a05a09a09a07/My-India-by-Jim-Corbett.pdf
    • http://muicuiu.dumb1.com/3a04a00a02a03a09/I-is-for-India-by-Prodeepta-Das.pdf
    • http://muicuiu.dumb1.com/8a09a05a07a04a07/India-by-Martin-H-rlimann.pdf
    • http://muicuiu.dumb1.com/5a09a05a09a00a08/In-Light-of-India-by-Octavio-Paz.pdf
    • http://muicuiu.dumb1.com/8a04a09a01a05a05/Ram-Ram-India-by-Alex-Thomson.pdf
    • http://muicuiu.dumb1.com/1a06a02a01a09a07/Dont-You-Want-Me-by-India-Knight.pdf
    • http://muicuiu.dumb1.com/