Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6cf5d99dc74a6fd…

MALICIOUS

PDF

24.0 KB Created: 2019-04-30 02:48:09 +01:00 Authoring application: mPDF 5.7
MD5: af0af61c12d819006f429cadfb3dda8b SHA-1: c00c1d718f0dd8fd0cdfd91863d617fd78df1a96 SHA-256: f6cf5d99dc74a6fdb8015257a809d14294591bdc080afb6c06662c0a0d1834cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles. While most individual URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or SEO manipulation tactic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. No scripts were extracted from this sample. The attack pattern is likely to direct users to external sites, potentially as a prelude to further malicious activity or for traffic generation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a06a00a08a06a05/An-Unpopular-War-From-Afkak-to-Bosbefok-Voices-of-South-African-National-Servicemen-by-J-H-Thompson.pdf
    • http://muicuiu.dumb1.com/4a03a07a06a03a09/In-Their-Own-Voices-African-Women-Writers-Talk-by-Adeola-James.pdf
    • http://muicuiu.dumb1.com/7a06a01a08a02a01/Trust-Me-Voices-from-the-South-by-J-W-Robitaille.pdf
    • http://muicuiu.dumb1.com/2a05a05a04a04a04/Freedom-s-Journey-African-American-Voices-of-the-Civil-War-by-Donald-Yacovone.pdf
    • http://muicuiu.dumb1.com/1a04a03a04a07a09/We-Were-There-Voices-of-African-American-Veterans-from-World-War-II-to-the-War-in-Iraq-by-Yvonne-Latty.pdf
    • http://muicuiu.dumb1.com/6a02a09a09a01a06/African-Women-Writing-Resistance-An-Anthology-of-Contemporary-Voices-by-Jennifer-Browdy-de-Hernandez.pdf
    • http://muicuiu.dumb1.com/5a07a07a09a02a09/The-Routledge-Reader-of-African-American-Rhetoric-The-Longue-Duree-of-Black-Voices-by-Michelle-Robinson.pdf
    • http://muicuiu.dumb1.com/4a05a01a03a09a08/South-of-Heaven-by-Jim-Thompson.pdf
    • http://muicuiu.dumb1.com/4a02a01a04a01a06/In-No-Uncertain-Terms-A-South-African-Memoir-by-Helen-Suzman.pdf
    • http://muicuiu.dumb1.com/7a06a01a05a07a09/The-Paperbook-of-South-African-English-Poetry-by-Michael-Chapman.pdf
    • http://muicuiu.dumb1.com/7a07a09a04a08a07/South-African-Township-Barbershops-amp-Salons-by-Simon-Weller.pdf
    • http://muicuiu.dumb1.com/8a02a08a00a03a09/Civilising-Grass-The-Art-of-the-Lawn-in-the-South-African-Highveld-by-Jonathan-Cane.pdf
    • http://muicuiu.dumb1.com/5a00a06a08a03a06/African-Atlantic-Cultures-and-the-South-Carolina-Lowcountry-by-Ras-Michael-Brown.pdf
    • http://muicuiu.dumb1.com/4a03a07a05a02a08/Flash-of-the-Spirit-African-amp-Afro-American-Art-amp-Philosophy-by-Robert-Farris-Thompson.pdf
    • http://muicuiu.dumb1.com/5a00a04a02a08a09/Through-Ebony-Eyes-What-Teachers-Need-to-Know-But-Are-Afraid-to-Ask-about-African-American-Students-by-Gail-L-Thompson.pdf
    • http://muicuiu.dumb1.com/7a09a09a04a03a05/Call-To-Home-African-Americans-Reclaim-The-Rural-South-by-Carol-B-Stack.pdf
    • http://muicuiu.dumb1.com/8a01a08a01a09a04/National-Audubon-Society-Field-Guide-to-North-American-Fossils-by-Ida-Thompson.pdf
    • http://muicuiu.dumb1.com/5a01a04a04a09a04/The-Tribe-of-Black-Ulysses-African-American-Lumber-Workers-in-the-Jim-Crow-South-by-William-P-Jones.pdf
    • http://muicuiu.dumb1.com/1a02a04a03a01a06/How-to-Build-a-Museum-Smithsonian-s-National-Museum-of-African-American-History-and-Culture-by-Tonya-Bolden.pdf
    • http://muicuiu.dumb1.com/7a09a00a01a07a02/Searching-African-Skies-The-Square-Kilometre-Array-and-South-Africa-s-Quest-to-Hear-the-Songs-of-the-Stars-by-Sarah-Wild.pdf
    • http://muicuiu.dumb1.com/5a07a07a09a02a09/The-Routledge-Reader-of-Afr