Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6e7027ab26c9126…

MALICIOUS

PDF

22.2 KB Created: 2019-05-07 06:13:06 +01:00 Authoring application: mPDF 5.7
MD5: 6f824e85710da429cb209cfb26dae47b SHA-1: 414bb77e0b162e8cf4d01b043fe12f1e678e377d SHA-256: f6e7027ab26c912693d88a0a0b0eef9dc78a233638c6cb4f6496573b46688730
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm. While the document body contains garbled text, the presence of numerous URLs suggests a potential attempt to redirect users to malicious sites or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a07a00a08a03a06/Club-Mephisto-Club-Mephisto-1-by-Annabel-Joseph.pdf
    • http://muicuiu.dumb1.com/1a04a08a02a03a05/The-Mephisto-Mark-The-Mephisto-Covenant-3-by-Trinity-Faegen.pdf
    • http://muicuiu.dumb1.com/6a07a04a07a07/Rizzoli-amp-Isles-Series-Collection-The-Surgeon-The-Apprentice-The-Sinner-Body-Double-Vanish-The-Mephisto-Club-Keeping-the-Dead-and-The-Killing-Place-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/9a05a02a04a08a07/The-Rizzoli-amp-Isles-Series-9-Book-Bundle-The-Surgeon-The-Apprentice-The-Sinner-Body-Double-Vanish-The-Mephisto-Club-The-Keepsake-Ice-Cold-The-Silent-Girl-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a00a06a00/Tess-Gerritsen-Collection-The-Mephisto-Club-Call-After-Midnight-In-Their-Footsteps-Gravity-Whistleblower-Under-The-Knife-Stolen-Presumed-Guilty-Keeper-Of-The-Bride-by-Tess-Gerritsen.pdf
    • http://muicuiu.dumb1.com/2a01a03a07a04a07/Madame-Mephisto-by-A-M-Bakalar.pdf
    • http://muicuiu.dumb1.com/3a05a06a00a05a04/The-Zig-Zag-Girl-Stephens-amp-Mephisto-Mystery-1-by-Elly-Griffiths.pdf
    • http://muicuiu.dumb1.com/2a06a07a01a09a04/The-Vanishing-Box-Stephens-amp-Mephisto-Mystery-4-by-Elly-Griffiths.pdf
    • http://muicuiu.dumb1.com/4a09a02a02a03a07/The-Redemption-of-Ajax-The-Mephisto-Covenant-1-by-Trinity-Faegen.pdf
    • http://muicuiu.dumb1.com/3a06a06a03a05a05/Club-Girl-Hell-Brigade-Motorcycle-Club-Book-1-by-Evelyn-Glass.pdf
    • http://muicuiu.dumb1.com/7a01a01a03a00a08/El-Club-de-Los-Suicidas-The-Suicide-Club-by-Robert-Louis-Stevenson.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a07a05a02/RIDERS-CLUB--2012-2-No-454-by-Rider-39-s-Club.pdf
    • http://muicuiu.dumb1.com/1a01a07a05a06a01a01/RIDERS-CLUB--2009-2-No-418-by-Rider-39-s-Club.pdf
    • http://muicuiu.dumb1.com/7a02a05a09a04a03/Constitution-Rules-and-Regulations-of-the-Rideau-Club-Adopted-29th-August-1865-by-Rideau-Club.pdf
    • http://muicuiu.dumb1.com/4a04a05a03a08a05/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/9a05a00a07a09a02/2nd-Club---Verkauft-The-Club-2-by-T-C-Jayden.pdf
    • http://muicuiu.dumb1.com/3a06a05a02a04a04/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/1a00a04/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/8a02a05a07a01a04/THE-CUCKOLDRESS-CLUB-A-wife-love-s-her-work-as-a-Dominatrix-and-Escort-but-the-chance-to-join-The-Cuckoldress-Club-unleashes-firs-of-passion-in-her-by-Carla-Delacourt.pdf
    • http://muicuiu.dumb1.com/7a05a01a06a02a09/Kisah-Cinta-di-Curry-Club-04-Curry-Club-Ai-Ni-Kite-No-I-4-by-Kiyoko-Arai.pdf
    • http://muicuiu.dumb1.com/1a00a07a01a00a06a00/Tess-Gerritsen-C