Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3c1185c69c2c701…

MALICIOUS

PDF

23.3 KB Created: 2019-05-01 07:43:02 +01:00 Authoring application: mPDF 5.7
MD5: 731816eb80b9c7e1ef3499b68261c6fd SHA-1: 58e217a2746897e9ca866df71ee7d8e9d89c823c SHA-256: e3c1185c69c2c7018e02be744633ca58047d9af33fed91a6b5f84921149fe84c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious with high confidence. The embedded URLs, while appearing to link to books, are likely part of a link farm designed to manipulate search engine results or redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a04a04a08a00a00/Redemption-by-Jacquelin-Thomas.pdf
    • http://muicuiu.dumb1.com/6a08a08a06a06a00/Only-for-You-The-Dugrandpres-of-Charleston-2-by-Jacquelin-Thomas.pdf
    • http://muicuiu.dumb1.com/6a02a06a04a05a06/The-Ideal-Wife-by-Jacquelin-Thomas.pdf
    • http://muicuiu.dumb1.com/2a01a06a07a04a04/Forever-My-Baby-The-Dugrandpres-of-Charleston-1-by-Jacquelin-Thomas.pdf
    • http://muicuiu.dumb1.com/3a09a03a00a05a09/Divine-Secrets-Divine-and-Friends-3-by-Jacquelin-Thomas.pdf
    • http://muicuiu.dumb1.com/4a02a05a02a01a01/The-Odd-Thomas-Series-4-Book-Bundle-Odd-Thomas-Forever-Odd-Brother-Odd-Odd-Hours-Odd-Thomas-1-4-by-Dean-Koontz.pdf
    • http://muicuiu.dumb1.com/9a08a05a02a05a07/Tess-of-the-D-urbervilles-by-Thomas-Hardy-Illustrated-Delphi-Parts-Edition-Thomas-Hardy-by-Thomas-Hardy.pdf
    • http://muicuiu.dumb1.com/9a08a05a02a08a09/Far-from-the-Madding-Crowd-by-Thomas-Hardy-Illustrated-Delphi-Parts-Edition-Thomas-Hardy-by-Thomas-Hardy.pdf
    • http://muicuiu.dumb1.com/8a03a07a03a06a03/Thomas-Calculus-Early-Transcendentals-Single-Variable-by-George-B-Thomas-Jr-.pdf
    • http://muicuiu.dumb1.com/6a07a05a06a02a04/The-Style-of-Connectedness-Gravity-s-Rainbow-and-Thomas-Pynchon-by-Thomas--Moore.pdf
    • http://muicuiu.dumb1.com/1a05a01a01a01a04/Timeless-Thomas-How-Thomas-Edison-Changed-Our-Lives-by-Gene-Barretta.pdf
    • http://muicuiu.dumb1.com/5a03a05a06a01a00/L-Utopie-Int-grale-Livres-1-et-2-de-Thomas-More-French-Edition-by-Thomas-More.pdf
    • http://muicuiu.dumb1.com/9a09a05a07a04a09/Dylan-Thomas-A-Farm-Two-Mansions-and-a-Bungalow-by-David-N-Thomas.pdf
    • http://muicuiu.dumb1.com/1a03a07a06a00a07/Collected-Poems-1945-1990-R-S-Thomas-by-R-S-Thomas.pdf
    • http://muicuiu.dumb1.com/1a04a01a03a05a04/Shakespeare-and-Co-Christopher-Marlowe-Thomas-Dekker-Ben-Jonson-Thomas-Middleton-John-Fletcher-and-the-Other-Players-in-His-Story-by-Stanley-Wells.pdf
    • http://muicuiu.dumb1.com/1a09a02a05a05a03/Thomas-Jefferson-s-Creme-Brulee-How-a-Founding-Father-and-His-Slave-James-Hemings-Introduced-French-Cuisine-to-America-by-Thomas-J-Craughwell.pdf
    • http://muicuiu.dumb1.com/8a02a00a07a06a02/Fabulous-Animals-at-the-Court-of-Science-A-17th-Century-Debate-Between-Sir-Thomas-Browne-and-Alexander-Ross-by-Thomas-Browne.pdf
    • http://muicuiu.dumb1.com/9a07a07a07a03a07/Totenham-Court-a-Pleasant-Comedy-Acted-at-the-Private-House-in-Salisbury-Court-by-Thomas-Nabbs-1639-by-Thomas-Nabbes.pdf
    • http://muicuiu.dumb1.com/7a01a03a03a03a09/Tess-of-the-d-Urbervilles-By-Thomas-Hardy-Illustrated-amp-Unabridged-Free-Bonus-Audiobook-by-Thomas-Hardy.pdf
    • http://muicuiu.dumb1.com/1a07a02a00a09a08/Odd-Thomas-Odd-Thomas-1-by-Dean-Koontz.pdf
    • http://muicuiu.dumb1.com/9a08a05a02a05a07/Tess-of-the-D-urbervilles-by-Thomas-Hardy-Illustrated-Delphi-Parts-Edition-Thomas-Har