Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1e2d5070833b157…

MALICIOUS

PDF

15.2 KB Created: 2019-04-30 07:59:20 +01:00 Authoring application: mPDF 5.7
MD5: 3af0a75dc7dfa70df950b29a5fa464d2 SHA-1: a1fd6d99784732d331a5cbd8c449be21a18d6d4e SHA-256: f1e2d5070833b1571ecab3643551c37131fa831d36c830d741a12a35d5225acf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were labeled as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a09a02a08a05a06/The-Machine-Blood-and-Destiny-1-by-E-C-Jarvis.pdf
    • http://muicuiu.dumb1.com/3a09a00a05a01a01/The-Machine-Blood-and-Destiny-1-by-E-C-Jarvis.pdf
    • http://muicuiu.dumb1.com/3a07a04a03a08a02/War-Machine-Destiny-in-the-Shadows-1-by-Maggie-Lynn-Heron-Heidel.pdf
    • http://muicuiu.dumb1.com/2a00a08a00a06a05/Blood-Passage-Blood-Destiny-2-by-Connie-Suttle.pdf
    • http://muicuiu.dumb1.com/2a06a01a05a07a00/Blood-Destiny-Blood-Curse-1-by-Tessa-Dawn.pdf
    • http://muicuiu.dumb1.com/1a08a08a08a00a06/Blood-Wager-Blood-Destiny-1-by-Connie-Suttle.pdf
    • http://muicuiu.dumb1.com/2a00a06a02a05a04/Blood-Queen-Blood-Destiny-6-by-Connie-Suttle.pdf
    • http://muicuiu.dumb1.com/2a00a09a05a08a01/Blood-Destiny-Blood-Curse-1-by-Tessa-Dawn.pdf
    • http://muicuiu.dumb1.com/8a02a03a03a01/Destiny-with-Blood-by-Pet-Torres.pdf
    • http://muicuiu.dumb1.com/7a01a05a07a05/Destiny-s-Blood-by-Marie-Bilodeau.pdf
    • http://muicuiu.dumb1.com/3a06a09a02a03a08/Alex-s-Destiny-Defender-s-Blood-1-by-A-K-Michaels.pdf
    • http://muicuiu.dumb1.com/2a07a07a05a01a06/Bloodmagic-Blood-Destiny-2-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/2a02a00a04a05a04/Bloodrage-Blood-Destiny-3-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/3a07a03a09a03a08/Bloodlust-Blood-Destiny-5-by-Helen-Harper.pdf
    • http://muicuiu.dumb1.com/1a07a08a05a04a05/Blood-of-Destiny-Witch-Fairy-6-by-Bonnie-Lamer.pdf
    • http://muicuiu.dumb1.com/6a03a03a06a08a08/George-Jarvis-his-journal-and-related-documents-by-George-Jarvis.pdf
    • http://muicuiu.dumb1.com/2a08a07a03a06a03/Machine-Metal-Magic-Mind-Machine-1-by-Hanna-Dare.pdf
    • http://muicuiu.dumb1.com/7a09a03a02a04a04/Good-War-Great-Men-The-detailed-accounts-of-a-machine-gun-battalion-during-World-War-I-313th-Machine-Gun-Battalion-by-Andrew-J-Capets.pdf
    • http://muicuiu.dumb1.com/2a02a03a03a02/They-Call-Me-Destiny-by-Destiny-Kalser-with-Fern-Field-Brooks.pdf
    • http://muicuiu.dumb1.com/3a08a01a07a06a01/Dark-Destiny-Destiny-Novella-Trilogy-1-by-Kari-Gray.pdf