Malicious PDF — malware analysis report

Static analysis result for SHA-256 e25c342dd9de301e…

MALICIOUS

PDF

24.9 KB Created: 2019-04-29 23:37:40 +01:00 Authoring application: mPDF 5.7
MD5: cd8f0c4967385f899b55d60209f3db37 SHA-1: 0e4d1d649d68c772e7cae023b71e8ec1c326b91e SHA-256: e25c342dd9de301ee3a2325ba21ba7b36b3145240338137b648c312e70ffe9a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute further malicious content. The primary attack pattern observed is the creation of a link farm designed to direct users to potentially harmful websites. No scripts were extracted, and the document body was unreadable, limiting further analysis of specific user lures.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a02a04a04a05a03/Awakened-Age-Of-Expansion---A-Kurtherian-Gambit-Series-The-Ascension-Myth-1-by-Ell-Leigh-Clarke.pdf
    • http://muicuiu.dumb1.com/3a02a05a08a07a04/Cloaked-Age-Of-Expansion---A-Kurtherian-Gambit-Series-The-Ascension-Myth-7-by-Ell-Leigh-Clarke.pdf
    • http://muicuiu.dumb1.com/3a02a05a00a02a03/Activated-Age-Of-Expansion---A-Kurtherian-Gambit-Series-The-Ascension-Myth-2-by-Ell-Leigh-Clarke.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a08a07a00/Exploration-Age-of-Expansion---A-Kurtherian-Gambit-Series-The-Ghost-Squadron-2-by-Sarah-Noffke.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a02a04/Impersonation-Age-of-Expansion---A-Kurtherian-Gambit-Series-The-Ghost-Squadron-5-by-Sarah-Noffke.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a05a04/Endless-Advance-Age-of-Expansion---A-Kurtherian-Gambit-Series-Uprise-Saga-2-by-Amy-DuBoff.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a01a09/Degeneration-Age-of-Expansion---A-Kurtherian-Gambit-Series-The-Ghost-Squadron-4-by-Sarah-Noffke.pdf
    • http://muicuiu.dumb1.com/1a01a04a06a09a06a01/Prime-Enforcer-Age-of-Expansion---A-Kurtherian-Gambit-Series-Valerie-s-Elites-3-by-Justin-Sloan.pdf
    • http://muicuiu.dumb1.com/3a02a05a08a04a09/Alpha-Class---Engineering-A-Kurtherian-Gambit-Series-The-Etheric-Academy-2-by-T-S-Paul.pdf
    • http://muicuiu.dumb1.com/3a02a04a04a06a09/Angel-of-Reckoning-A-Kurtherian-Gambit-Series-Reclaiming-Honor-4-by-Justin-Sloan.pdf
    • http://muicuiu.dumb1.com/3a02a04a02a02a08/Nomad-s-Galaxy-A-Kurtherian-Gambit-Series-Terry-Henry-Walton-Chronicles-10-by-Craig-Martelle.pdf
    • http://muicuiu.dumb1.com/3a02a05a03a00a09/Darkness-Rises-Age-Of-Magic---A-Kurtherian-Gambit-Series-The-Rise-of-Magic-6-by-C-M-Raymond.pdf
    • http://muicuiu.dumb1.com/3a02a04a02a04a01/Claimed-By-Honor-A-Kurtherian-Gambit-Series-Reclaiming-Honor-2-by-Justin-Sloan.pdf
    • http://muicuiu.dumb1.com/1a05a08a02a01a08/Reawakening-Age-Of-Magic---A-Kurtherian-Gambit-Series-The-Rise-of-Magic-2-by-C-M-Raymond.pdf
    • http://muicuiu.dumb1.com/3a02a04a02a04a07/We-Will-Build-The-Kurtherian-Gambit-8-by-Michael-Anderle.pdf
    • http://muicuiu.dumb1.com/3a02a04a02a05a01/Kneel-Or-Die-The-Kurtherian-Gambit-7-by-Michael-Anderle.pdf
    • http://muicuiu.dumb1.com/3a02a03a09a09a05/Forever-Defend-The-Kurtherian-Gambit-17-by-Michael-Anderle.pdf
    • http://muicuiu.dumb1.com/3a04a08a09a09a09/Queen-Bitch-The-Kurtherian-Gambit-2-by-Michael-Anderle.pdf
    • http://muicuiu.dumb1.com/3a02a04a02a04a05/Release-The-Dogs-of-War-The-Kurtherian-Gambit-10-by-Michael-Anderle.pdf
    • http://muicuiu.dumb1.com/2a01a04a07a08a03/Myth-of-Perfection-Confessions-of-a-Housewife-Myth-Series-by-Kate-Maxwell.pdf