Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9e2d2c563cb29b8…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 04:06:15 +01:00 Authoring application: mPDF 5.7
MD5: f81e818e46832a9b282e47ec6b90be1b SHA-1: dc12a35dc366a87b095cb3582ce1f4e5fd2555bf SHA-256: e9e2d2c563cb29b8b315897585d5b9cd72df99b77a2b1dcb2da179265470100f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, characteristic of a link farm or SEO poisoning attack. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 21 external links, suggesting the document's purpose is to distribute these links. While the extracted URLs are currently marked as benign, the sheer volume and the critical heuristic firing strongly suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu
    • http://muicuiu.dumb1.com/1a00a06a00a04a08a09/Victory-Legacy-Fleet-Trilogy-3-by-Nick-Webb.pdf
    • http://muicuiu.dumb1.com/1a05a02a06a09a08/The-Legacy-by-Katherine-Webb.pdf
    • http://muicuiu.dumb1.com/1a03a02a05a00a07/The-Legacy-by-Katherine-Webb.pdf
    • http://muicuiu.dumb1.com/3a00a09a05a07a00/A-Victory-that-Counts-The-Impaler-Legacy-2-by-Ioana-Visan.pdf
    • http://muicuiu.dumb1.com/9a07/Warship-Black-Fleet-Trilogy-1-by-Joshua-Dalzelle.pdf
    • http://muicuiu.dumb1.com/4a08a04a06a04a01/The-Stone-House-Legacy-Legacy-Trilogy-1-by-Wanda-Dehaven-Pyle.pdf
    • http://muicuiu.dumb1.com/2a00a08a05a07a05/The-End-and-the-Beginning-Pope-John-Paul-II----The-Victory-of-Freedom-the-Last-Years-the-Legacy-by-George-Weigel.pdf
    • http://muicuiu.dumb1.com/3a06a07a06a02a02/Children-of-the-Fleet-Fleet-School-1-by-Orson-Scott-Card.pdf
    • http://muicuiu.dumb1.com/8a09a02a02a05a00/The-Fleet-the-Gods-Forgot-The-U-S-Asiatic-Fleet-in-World-War-II-by-W-G-Winslow.pdf
    • http://muicuiu.dumb1.com/3a02a06a00a06a02/Orion-Fleet-Rebel-Fleet-2-by-B-V-Larson.pdf
    • http://muicuiu.dumb1.com/4a01a05a03a07a01/Victory-Run-3-The-Story-of-Victory-Payne-3-by-Devon-Hartford.pdf
    • http://muicuiu.dumb1.com/2a08a07a00a00a06/Passion-s-Victory-Victory-3-by-K-C-Kendricks.pdf
    • http://muicuiu.dumb1.com/4a02a05a02a04a05/Star-Marines-The-Legacy-Trilogy-3-by-Ian-Douglas.pdf
    • http://muicuiu.dumb1.com/4a04a04a08a09a08/Legacy-The-Guardian-Trilogy-3-by-Robin-Helm.pdf
    • http://muicuiu.dumb1.com/5a00a00a00a08a08/Texas-Legacy-Trilogy-by-DiAnn-Mills.pdf
    • http://muicuiu.dumb1.com/8a01a09a06a06/X-Men-The-Legacy-Quest-Trilogy-Book-1-by-Steve-Lyons.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a06a04/X-Men-The-Legacy-Quest-Trilogy-Book-2-by-Steve-Lyons.pdf
    • http://muicuiu.dumb1.com/6a04a04a08a08a04/Dawn-of-Illumination-Oracle-s-Legacy-Trilogy-3-by-R-B-Holbrook.pdf
    • http://muicuiu.dumb1.com/4a05a07a04a05a08/Nick-s-Time-Out-Nick-s-Awakening-2-by-Simon-Strange.pdf
    • http://muicuiu.dumb1.com/4a09a06a07a00a02/Legacy-of-the-Darksword-The-Darksword-Trilogy-4-by-Margaret-Weis.pdf