Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7347ab03a17e421…

MALICIOUS

PDF

16.2 KB Created: 2019-04-30 03:47:35 +01:00 Authoring application: mPDF 5.7
MD5: afeb07f55af77f381d942c5543dd6b50 SHA-1: a75ee96854cdd79fa8f464e4cb4b5e65f78e18f0 SHA-256: f7347ab03a17e421ca55b4fc5bffae7508a64c5f4d31168e946b57a748bc3f27
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a06a06a02a03a09/Someone-Like-Her-K2-Team-2-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/3a00a02a04a06a05/Crazy-for-Her-K2-Team-1-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/4a03a03a09a00a02/Crazy-for-Her-K2-Team-1-by-Sandra-Owens.pdf
    • http://muicuiu.dumb1.com/1a08a06a02a08a01/The-Ultimate-Team-Juxtapose-City-4-by-Tricia-Owens.pdf
    • http://muicuiu.dumb1.com/1a02a08a03a05a07/The-Team-Formula-A-Leadership-Tale-of-a-Team-Who-Found-Their-Way-by-Mandy-Flint.pdf
    • http://muicuiu.dumb1.com/4a01a04a06a02a05/Team-Niklas-The-Saints-Team-3-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/2a08a02a03a00a09/Team-Lucas-The-Saints-Team-1-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/2a08a02a08a03a00/Team-Tom-s-The-Saints-Team-2-by-Ally-Adams.pdf
    • http://muicuiu.dumb1.com/9a05a04a08a07a00/Team-Captain-Leadership-C-L-A-S-S-Curriculum-Module-II-of-III-Team-Leadership-The-Dynamics-and-Challenges-of-Leading-Others-in-Organizations-and-Teams-by-Dr-Philip-Willenbrock.pdf
    • http://muicuiu.dumb1.com/1a09a02a04a00a09/Two-Man-Team-Team-2-by-Jet-Mykles.pdf
    • http://muicuiu.dumb1.com/2a09a04a02a09a04/Space-Team-Space-Team-1-by-Barry-J-Hutchison.pdf
    • http://muicuiu.dumb1.com/2a03a00a06a04a06/Smoke-Screen-Sandra-Brown-by-Sandra-Brown.pdf
    • http://muicuiu.dumb1.com/4a01a03a08a08a08/Out-of-the-Darkness-Taken-2-by-J-C-Owens.pdf
    • http://muicuiu.dumb1.com/5a07a04a06a00a02/Ultimo-viene-il-leader-Perch-alcuni-team-sono-coesi-e-altri-no-Perch-alcuni-team-sono-coesi-e-altri-no-by-Simon-Sinek.pdf
    • http://muicuiu.dumb1.com/3a01a06a02a01a04/Dog-Whisperer-by-Paul-Owens.pdf
    • http://muicuiu.dumb1.com/2a08a07a01a09a07/It-Must-Be-Love-by-Sharon-Owens.pdf
    • http://muicuiu.dumb1.com/2a05a05a03a01a05/The-Emperor-s-Wolf-by-J-C-Owens.pdf
    • http://muicuiu.dumb1.com/7a05a09a04a03a01/Love-amp-College-by-C-M-Owens.pdf
    • http://muicuiu.dumb1.com/2a08a02a01a07/Cry-of-the-Kalahari-by-Mark-Owens.pdf
    • http://muicuiu.dumb1.com/3a04a06a03a03a00/Island-of-Dragons-by-Lindsey-Owens.pdf