Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0b0926e265a661d…

MALICIOUS

PDF

23.3 KB Created: 2019-04-30 04:50:37 +01:00 Authoring application: mPDF 5.7
MD5: 01cb2e718f546b409bc038d8a5845f54 SHA-1: e87e946c0c687519cb867e34263fa8bbcd668d3f SHA-256: e0b0926e265a661d9b8a7ecf8de33ea13c19cdf6d2a3a542f61ca773d48d259f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm or SEO spam technique. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to redirect users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9926

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a00a07a05a05a04/My-Mother-s-Boyfriend-and-Me-by-Alice-Jacoby.pdf
    • http://muicuiu.dumb1.com/3a03a04a07a05a03/Her-Mother-s-Daughter-by-Alice-Fitzgerald.pdf
    • http://muicuiu.dumb1.com/2a04a02a04a05a02/The-World-s-Worst-Boyfriend-Bad-Boyfriend-1-by-Erika-Kelly.pdf
    • http://muicuiu.dumb1.com/2a02a06a09a02a04/Book-Boyfriend-Series-Collector-s-Edition-Boxed-Set-Book-Boyfriend-1-3-5-bonus-by-Erin-Noelle.pdf
    • http://muicuiu.dumb1.com/8a02a00a05a03a06/My-Mafioso-Boyfriend---Complete-Series-My-Mafioso-Boyfriend-1-5-by-Eliza-Stout.pdf
    • http://muicuiu.dumb1.com/6a09a04a00a09a09/Alice-Aventuras-de-Alice-no-Pa-s-das-Maravilhas-amp-Atrav-s-do-Espelho-e-o-Oue-Alice-Encontrou-Por-L-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/9a07a03a05a07a03/The-Alice-Books-Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/3a00a02a02a02a00/Life-After-Genius-by-M-Ann-Jacoby.pdf
    • http://muicuiu.dumb1.com/1a01a04a09a07a02a00/The-Muslim-Challenge-by-Douglas-Jacoby.pdf
    • http://muicuiu.dumb1.com/5a08a08a08a02a03/Le-Protecteur-Du-Citoyen-Essais-by-Daniel-Jacoby.pdf
    • http://muicuiu.dumb1.com/4a03a08a08a03a00/House-and-Philosophy-Everybody-Lies-by-Henry-Jacoby.pdf
    • http://muicuiu.dumb1.com/7a07a00a02a02a03/Dialectic-of-Defeat-Contours-of-Western-Marxism-by-Russell-Jacoby.pdf
    • http://muicuiu.dumb1.com/1a02a07a05a09a01/The-Strange-Career-of-William-Ellis-The-Texas-Slave-Who-Became-a-Mexican-Millionaire-by-Karl-Jacoby.pdf
    • http://muicuiu.dumb1.com/5a09a08a06a05a04/Have-Mother-Will-Travel-A-Mother-and-Daughter-Discover-Themselves-Each-Other-and-the-World-by-Claire-Fontaine.pdf
    • http://muicuiu.dumb1.com/1a03a00a07a02a08/Whatever-Mother-Says-A-True-Story-of-a-Mother-Madness-and-Murder-by-Wensley-Clarkson.pdf
    • http://muicuiu.dumb1.com/6a00a03a08a09a09/Alice-s-Adventures-in-Wonderland-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/7a07a00a09a07a05/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/4a03a09a07a02a01/The-Annotated-Alice-Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/5a08a01a07a02a09/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://muicuiu.dumb1.com/2a02a03a03a07a04/Today-I-m-Alice-a-memoir-of-multiple-personality-disorder-by-Alice-Jamieson.pdf
    • http://muicuiu.dumb1.com/9a07a03a05a07a03/The-Alice