Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5977955f6892e4b…

MALICIOUS

PDF

18.9 KB Created: 2019-05-01 05:13:27 +01:00 Authoring application: mPDF 5.7
MD5: 528f69c8a74ba0bc3de96d54d640782b SHA-1: 7e47c6991ef21bf268f5f6b5a2d0a2d28ee4360d SHA-256: f5977955f6892e4b3f0c598b9ae2718ff86d70b8bd74ea41f4ff5006c2adb98d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, a technique often used for SEO manipulation or to redirect users to malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself suggests a link-farming or redirection attack. The primary IOCs are the numerous URLs embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.c
    • http://muicuiu.dumb1.com/1a03a00a00a07a06/The-West-Series-Boxset-West-1-3-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/1a03a00a09a07a02/Roping-Ryan-West-6-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/1a04a07a01a08a00/Missy-s-Moment-West-4-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/1a01a05a09a06a00a04/Haley-Halten-West-3-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/1a01a09a02a08a07a08/Krups-Encyclopedia-Of-Coffee-And-Espresso-by-Jill-West.pdf
    • http://muicuiu.dumb1.com/2a09a03a08a09/The-Real-Wild-West-The-101-Ranch-and-the-Creation-of-the-American-West-by-Michael-Wallis.pdf
    • http://muicuiu.dumb1.com/3a04a03a02a01a08/West-Wind-s-Fool-and-Other-Stories-of-the-Devil-s-West-by-Laura-Anne-Gilman.pdf
    • http://muicuiu.dumb1.com/5a01a09a09a08a08/The-East-Face-of-Helicon-West-Asiatic-Elements-in-Greek-Poetry-and-Myth-by-M-L-West.pdf
    • http://muicuiu.dumb1.com/4a03a07a08a06a00/Fela-From-West-Africa-to-West-Broadway-by-Trevor-Schoonmaker.pdf
    • http://muicuiu.dumb1.com/1a09a07a03a06/Three-Plays-by-Mae-West-Sex-The-Drag-The-Pleasure-Man-by-Mae-West.pdf
    • http://muicuiu.dumb1.com/3a06a01a03a04a06/Pride-Series-Book-One-amp-Two-The-Pride-1-2-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/2a01a00a08a06a05/How-the-West-Was-Once---A-History-of-West-Olympia-by-Larry-Smith-39-s-8th-grade-English-class-Jefferson-High-School-Olympia.pdf
    • http://muicuiu.dumb1.com/2a09a06a08a02/This-Is-the-West-by-Robert-West-Howard.pdf
    • http://muicuiu.dumb1.com/1a07a03a00a00a01/Good-Witch-of-the-West-The-Girl-of-Sera-Field-The-God-Witch-of-the-West-Novel-1-by-Noriko-Ogiwara.pdf
    • http://muicuiu.dumb1.com/3a07a06a05a06a03/Inspector-West-Takes-Charge-Inspector-West-1-by-John-Creasey.pdf
    • http://muicuiu.dumb1.com/5a09a04a05a07a06/Ernest-Hemingway-in-Key-West-A-Guide-Famous-Footsteps-Series-by-Marsha-Bellavance-Johnson.pdf
    • http://muicuiu.dumb1.com/1a05a05a04a06a04/Ascension-Science-fiction-and-fantasy-series-Tales-of-Cinnamon-City-3-by-Peter-James-West.pdf
    • http://muicuiu.dumb1.com/1a02a05a04a05a00/Last-Resort-Grayton-1-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/9a06a04a02a09a03/Last-Resort-Grayton-1-by-Jill-Sanders.pdf
    • http://muicuiu.dumb1.com/4a05a08a04a06a03/West-of-Eden-West-of-Eden-1-by-Harry-Harrison.pdf