Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec652704a26103fb…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 07:44:51 +01:00 Authoring application: mPDF 5.7
MD5: b10e1f566797ec8215ab0b398dec6b27 SHA-1: 65dd7582bbf78768e0c93e14e2b709d6621c61e7 SHA-256: ec652704a26103fb969ac879e563100d2f97f4f634863262f521471b9ce69d03
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to a website that appears to host pirated books. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded URLs are likely intended to drive traffic to the site, potentially as a lure for further malicious activity or to generate ad revenue.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a07a01a00a06a00/Tess-Gerritsen-Collection-The-Mephisto-Club-Call-After-Midnight-In-Their-Footsteps-Gravity-Whistleblower-Under-The-Knife-Stolen-Presumed-Guilty-Keeper-Of-The-Bride-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a01a02a05/A-Rizzoli-and-Isles-Series-Collection-5-Books-Set-By-Tess-Gerritsen-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/4a09a03a07a01a04/Last-to-Die-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/3a01a07a01a06a07/Whistleblower-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a08a06a05a03a08/Bloodstream-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/4a00a06a09a02/Gravity-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/2a09a01a01a01/The-Silent-Girl-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a08a05a00/Playing-with-Fire-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/3a09a04a06a03a09/Keeper-of-the-Bride-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a08a06a08a05a01/The-Killing-Place-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/2a06a03a01a02a09/Playing-with-Fire-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a09a00a05a03a01/The-Bone-Garden-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a00a05a06/Love-s-Masquerade-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/8a02a04a03a03a04/The-Surgeon-Rizzoli-amp-Isles-1-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/3a06a02a05a05/Ice-Cold-Rizzoli-amp-Isles-8-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/2a06a03a01a08a08/John-Doe-Rizzoli-amp-Isles-9-5-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a00a03a01/Presumed-Guilty-In-Their-Footsteps-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a01a05a07a03a05a07/Angst-In-Deinen-Augen-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/2a03a07a08a05a02/The-Silent-Girl-Rizzoli-amp-Isles-9-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a01a02a03/Do-or-Die-Call-After-Midnight-Keeper-of-the-Bride-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a08a05a00/Pla