Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8ab62d23cf6c145…

MALICIOUS

PDF

25.5 KB Created: 2019-04-30 04:13:40 +01:00 Authoring application: mPDF 5.7
MD5: aea4b04638e3c9a194cd229f9fc566d2 SHA-1: 598900068c12cf8fd90a9ee4812afd656f7ffbeb SHA-256: e8ab62d23cf6c145a8203abc2025336197e61329eb7cf5f382d266030c00d35c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. The ML classifier also flagged this document as malicious. The primary attack pattern observed is the attempt to direct the user to a link farm, likely for further malicious redirection or content delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a08a05a06a09/Hero-Homecoming-3-The-Legend-of-Drizzt-30-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a07a06a04a06a02/Legend-of-Drizzt-Collector-s-Edition-Vol-1-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a04a06a08a07/The-Legend-of-Drizzt-The-Collected-Stories-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a00a03a06a00/The-Companions-The-Sundering-1-Legend-of-Drizzt-24-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a03a07a01a09/Dungeons-amp-Dragons-The-Legend-of-Drizzt---Neverwinter-Tales-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a01a06a00a07a07/Gauntlgrym-Forgotten-Realms-Neverwinter-1-Legend-of-Drizzt-20-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a09a01a02a09/Night-of-the-Hunter-Companions-Codex-1-Legend-of-Drizzt-25-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a04a08a08a03a07/Rise-of-the-King-Companions-Codex-2-Legend-of-Drizzt-26-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a07a00a05a01/Sojourn-Forgotten-Realms-The-Dark-Elf-Trilogy-3-Legend-of-Drizzt-3-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a09a01a00a09a05/Sea-of-Swords-Forgotten-Realms-Paths-of-Darkness-4-Legend-of-Drizzt-13-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/7a04a08a01a00/The-Two-Swords-Forgotten-Realms-Hunter-s-Blades-3-Legend-of-Drizzt-16-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/7a05a01a07a05/The-Halfling-s-Gem-Forgotten-Realms-Icewind-Dale-3-Legend-of-Drizzt-6-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a02a01/Siege-of-Darkness-Forgotten-Realms-Legacy-of-the-Drow-3-Legend-of-Drizzt-9-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a08a06a01a06/The-Silent-Blade-Forgotten-Realms-Paths-of-Darkness-1-Legend-of-Drizzt-11-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a06a08a03a07/The-Crystal-Shard-Forgotten-Realms-Icewind-Dale-1-Legend-of-Drizzt-4-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/8a02a03a06a07/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/2a03a04a05a02a01/Neverwinter-Forgotten-Realms-Neverwinter-2-Legend-of-Drizzt-21-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a06a02a06a02a07/The-Halfling-s-Gem-The-Graphic-Novel-Legend-of-Drizzt-The-Graphic-Novel-6-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/4a06a02a07a00a04/Homeland-The-Graphic-Novel-Legend-of-Drizzt-The-Graphic-Novel-1-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/3a05a09a06a02a06/The-Dark-Elf-Trilogy-Forgotten-Realms-Dark-Elf-Trilogy-1-3-Legend-of-Drizzt-1-3-by-R-A-Salvatore.pdf
    • http://muicuiu.dumb1.com/