Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebae75437d4f4518…

MALICIOUS

PDF

17.7 KB Created: 2019-05-02 00:48:38 +01:00 Authoring application: mPDF 5.7
MD5: 1d60414c826991bb64fe4bcf4b9b19e3 SHA-1: 9a7faf3e58d7c58b68da8ce3950f9cdefb1e4f62 SHA-256: ebae75437d4f451848891e6823aaaa19d0adc721a9b5dccd29d9dc8183997a2c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged for containing a mass external link farm, with 24 links pointing to external domains. While most of these URLs were confirmed benign, the sheer volume and the heuristic firing suggest a potential attempt at SEO manipulation or a lure for users to click on potentially malicious links. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a08a09a09a02/Kicker-s-Journey-by-Lois-Cloarec-Hart.pdf
    • http://muicuiu.dumb1.com/6a05a01a05a05a05/Bitter-Fruit-by-Lois-Cloarec-Hart.pdf
    • http://muicuiu.dumb1.com/8a06a02a08a04a02/Walking-the-Labyrinth-by-Lois-Cloarec-Hart.pdf
    • http://muicuiu.dumb1.com/6a02a02a00a06a06/The-Ear-of-the-Heart-An-Actress-Journey-from-Hollywood-to-Holy-Vows-by-Dolores-Hart.pdf
    • http://muicuiu.dumb1.com/1a03a06a02a03a08/Mandie-and-the-Midnight-Journey-Mandie-Books-13-by-Lois-Gladys-Leppard.pdf
    • http://muicuiu.dumb1.com/1a02a02a06a00a03/Roughing-the-Kicker-Saints-and-Sinners-1-by-Eden-Butler.pdf
    • http://muicuiu.dumb1.com/1a00a00a02a01a07a02/Coole-Kicker-im-Fu-ballfieber-Der-siebte-Roman-by-Dieter-Winkler.pdf
    • http://muicuiu.dumb1.com/5a03a01a05a01a03/And-Here-s-the-Kicker-Conversations-with-21-Top-Humor-Writers-on-their-Craft-and-the-Industry-by-Mike-Sacks.pdf
    • http://muicuiu.dumb1.com/2a08a03a04a09a00/Damn-Good-Advice-For-People-with-Talent-How-To-Unleash-Your-Creative-Potential-by-America-s-Master-Communicator-George-Lois-by-George-Lois.pdf
    • http://muicuiu.dumb1.com/7a03a06a04a05a08/Lois-Lowry-by-Lois-Markham.pdf
    • http://muicuiu.dumb1.com/1a00a08a05a05a01a05/Zulu-Hart-George-Hart-1-by-Saul-David.pdf
    • http://muicuiu.dumb1.com/1a03a05a03a04a09/Shattered-Hart-The-Hart-Family-2-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/2a05a00a01a04a04/Finding-Hart-The-Hart-Family-6-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/4a06a09a04a06/Missing-Hart-The-Hart-Family-5-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/4a05a07a03a06a03/Finding-Hart-The-Hart-Family-6-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/8a01a02a07a05/Finding-Hart-The-Hart-Family-6-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/9a01a04a02a02a08/Wenn-es-hart-auf-hart-kommt-by-Ben-Horowitz.pdf
    • http://muicuiu.dumb1.com/1a01a06a09a01a04/Broken-Hart-The-Hart-Family-1-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/2a00a02a02a03a02/Missing-Hart-The-Hart-Family-5-by-Ella-Fox.pdf
    • http://muicuiu.dumb1.com/1a00a08a03a04a09a00/Geile-Verd-chtige-Hart-Genommen---Good-Cop-Bad-Cop-beim-Nymphomanenverh-r-Hart-und-Lustvoll-genommen-32-by-Rainer-Segen.pdf
    • http://muicuiu.dumb1.com/5a03a01a05a01a03/And-Here-s-the-Kicker-Conversations-with-21-Top-Humor-Writers-on-their-Craft-and-the-Industry-by-Mike-