Malicious PDF — malware analysis report

Static analysis result for SHA-256 e10ede6e8df2b8f1…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 03:49:49 +01:00 Authoring application: mPDF 5.7
MD5: 3673845ac5bad7a2cd53612319530ea2 SHA-1: ecb6ef991b2ee61e07c30c27ec086eea472d4eeb SHA-256: e10ede6e8df2b8f10e098db40974f0cd7b08fb98ab398c7e160e59a79294974d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' and the numerous URLs suggest the primary purpose is to redirect users to external sites. The specific URLs, while marked as benign in this analysis, are part of a pattern indicative of a link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a09a07a07a04/Ashes-and-Ice-Ashes-and-Ice-1-by-Rochelle-Maya-Callen.pdf
    • http://muicuiu.dumb1.com/1a01a02a08a09a04a01/Falling-Ashes-Ashes-to-Ashes-2-by-Annie-Anderson.pdf
    • http://muicuiu.dumb1.com/1a01a02a08a09a04a05/Rising-Ashes-Ashes-to-Ashes-3-by-Annie-Anderson.pdf
    • http://muicuiu.dumb1.com/2a00a00a09a08a06/Dead-Girl-s-Ashes-Dying-Ashes-1-by-Annathesa-Nikola-Darksbane.pdf
    • http://muicuiu.dumb1.com/7a06a02a08a08a05/Ashes-to-Ashes-The-Chronicles-of-Hugh-de-Singleton-Surgeon-8-by-Melvin-R-Starr.pdf
    • http://muicuiu.dumb1.com/8a09a01a00a03a00/Ashes-Ruhelose-Seelen-Ashes-3-part-1-of-2-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/8a06a08a05a03a05/Ashes-Pechschwarzer-Mond-Ashes-3-part-2-of-2-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/1a04a07a08a00a08/Ashes-to-Ashes-Experiment-in-Terror-8-by-Karina-Halle.pdf
    • http://muicuiu.dumb1.com/8a05a01a07a02/Ashes-to-Ashes-Kovac-and-Liska-1-by-Tami-Hoag.pdf
    • http://muicuiu.dumb1.com/2a05a01a09a08a01/Ashes-to-Ashes-Screenplay-by-Wayne-Gerard-Trotman.pdf
    • http://muicuiu.dumb1.com/3a01a02a00a09a04/Ashes-to-Ashes-The-Chloe-Files-1-by-Howard-Hopkins.pdf
    • http://muicuiu.dumb1.com/2a00a05a05a06a09/Ashes-to-Ashes-Blood-Ties-3-by-Jennifer-Armintrout.pdf
    • http://muicuiu.dumb1.com/5a07a04a01a06a00/Ashes-to-Ashes-The-Pyre-of-Karma-by-Haimes-Hensley.pdf
    • http://muicuiu.dumb1.com/2a01a07a05a09/Ashes-to-Ashes-America-s-Hundred-Year-Cigarette-War-the-Public-Health-and-the-Unabashed-Triumph-of-Philip-Morris-by-Richard-Kluger.pdf
    • http://muicuiu.dumb1.com/2a01a04a04a00a00/Pocketful-of-Posies-Ashes-Ashes-2-by-Jo-Treggiari.pdf
    • http://muicuiu.dumb1.com/3a00a06a03a04a03/Ashes-Ashes-Trilogy-1-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/3a05a01a01a01/Ashes-Ashes-Trilogy-1-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/8a02a04a07a02a04/Ashes-Ashes-1-by-Kelly-Cozy.pdf
    • http://muicuiu.dumb1.com/3a06a08a08a06/From-Ashes-From-Ashes-1-by-Molly-McAdams.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a01a03/From-Ashes-From-Ashes-1-by-Molly-McAdams.pdf
    • http://muicuiu.dumb1.com/8a05a01a07a02/Ashes-to-Ashes-Kovac-and-Liska-1-by-Tami-Hoa