Malicious PDF — malware analysis report

Static analysis result for SHA-256 f657a1466e77efd9…

MALICIOUS

PDF

20.3 KB Created: 2019-05-07 03:46:27 +01:00 Authoring application: mPDF 5.7
MD5: 16400c2b50f7fca0a1a24705c1ded3ff SHA-1: 5268a5d956955007199a6a52779e2831bca510d9 SHA-256: f657a1466e77efd934c81be6896b39d3aa8abe242b3033cd777c17eb906bad66
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, indicative of a link farm or phishing attempt. While the specific content of the document body is obfuscated, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests the intent is to lure users to external sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a09a01a05a01a05/We-the-Living-Sixtieth-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/3a01a07a00a00a09/We-the-Living-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/6a05a03a04a09a08/The-Early-Ayn-Rand-A-Selection-from-Her-Unpublished-Fiction-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/9a09a05a03a06/For-the-New-Intellectual-The-Philosophy-of-Ayn-Rand-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/2a05a05a01a07a01/The-Ayn-Rand-Lexicon-Objectivism-from-A-to-Z-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/9a08a01a06a08a08/Rand-McNally-streets-amp-highways-of-Chicagoland-by-Rand-McNally-and-Company.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a00a04a03/The-Very-Best-of-Fantasy-amp-Science-Fiction-Sixtieth-Anniversary-Anthology-by-Gordon-Van-Gelder.pdf
    • http://muicuiu.dumb1.com/7a06a04a05a09a02/Living-Russian-Revised-dictionary-The-Complete-Living-Language-Course-by-Nadya-Peterson.pdf
    • http://muicuiu.dumb1.com/8a08a09a03a08a01/Living-in-DC-An-Insider-s-Guide-How-to-Get-a-Job-and-Make-the-Most-of-Living-in-the-Nation-s-Capital-by-Kate-McFadyen.pdf
    • http://muicuiu.dumb1.com/6a00a06a07a08/Four-Quadrant-Living-Making-Healthy-Living-Your-New-Way-of-Life-by-Dina-Colman.pdf
    • http://muicuiu.dumb1.com/3a01a09a01a06a06/Eeny-Meeny-Miney-Mo-And-Still---Mo-Lessons-In-Living-From-Five-Frisky-Red-Squirrels-Living-Forest-3-by-Sam-Campbell.pdf
    • http://muicuiu.dumb1.com/2a05a09a00a00a06/The-Everything-Guide-to-Living-Off-the-Grid-A-back-to-basics-manual-for-independent-living-by-Terri-Reid.pdf
    • http://muicuiu.dumb1.com/1a01a07a05a09a07a02/Living-Loving-amp-Unlearning-A-Therapist-s-Guide-to-Healing-and-Living-Authentically-from-the-Inside-Out-by-Cynthia-Brennen.pdf
    • http://muicuiu.dumb1.com/3a06a07a01a03/Mindfulness-Living-in-the-Moment---Living-in-the-Breath-by-Amit-Ray.pdf
    • http://muicuiu.dumb1.com/7a05a08a03a04a01/Der-Streik-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/3a01a03a08a01a05/Anthem-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/4a00a00a02a00/Philosophy-Who-Needs-It-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/9a05a09a01a03a02/Atlas-Shrugged-by-Ayn-Rand.pdf
    • http://muicuiu.dumb1.com/8a00a02a01a05/The-Burning-Jacket-by-Nel-Rand.pdf
    • http://muicuiu.dumb1.com/4a06a08a03a02a08/The-Green-Man-and-Other-Stories-by-Rand-B-Lee.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a00a04a03/The-Very-Best-of-Fantasy-amp-Science-Fiction-Sixtieth-Anniversary-Ant