Malicious PDF — malware analysis report

Static analysis result for SHA-256 f77e5174bd9f4d74…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 08:37:35 +01:00 Authoring application: mPDF 5.7
MD5: 59a47bdeb7ea986a198d9818cd56d5a3 SHA-1: 0fa0e3a25434e8ade5de47646d9a1c76a194bf5a SHA-256: f77e5174bd9f4d74420a90d69b67fa75d827ee2a4dca2b9bc26bdc92fd28f7a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of external links, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a collection of external PDF documents, likely for SEO poisoning or to host malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a02a00a05a09/Robert-Frost-The-Work-of-Knowing-With-a-New-Afterword-by-Richard-Poirier.pdf
    • http://muicuiu.dumb1.com/3a07a05a02a09a08/Complete-Poems-Of-Robert-Frost-1949-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/6a02a07a00a02a06/RENEWAL-OF-LITERATURE-by-Richard-Poirier.pdf
    • http://muicuiu.dumb1.com/5a08a00a04a06a08/Mythos-Academy-Bundle-First-Frost-Touch-of-Frost-Kiss-of-Frost-amp-Dark-Frost-by-Jennifer-Estep.pdf
    • http://muicuiu.dumb1.com/6a02a07a00a01a09/A-World-Elsewhere-The-Place-of-Style-in-American-Literature-by-Richard-Poirier.pdf
    • http://muicuiu.dumb1.com/4a05a07a09a06a04/Frost-Poems-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/2a03a03a01a05/The-Poetry-of-Robert-Frost-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/7a07a06a04a09a04/In-Between-Work-and-Play-Jocelyn-Frost-1-by-Relina-Skye.pdf
    • http://muicuiu.dumb1.com/1a08a04a07a03a07/A-Book-of-Knowing-and-Not-Knowing-A-Handbook-for-the-Information-Age-by-Martin-Gover.pdf
    • http://muicuiu.dumb1.com/4a01a05a06a02a02/Original-Wisdom-Stories-of-an-Ancient-Way-of-Knowing-by-Robert-Wolff.pdf
    • http://muicuiu.dumb1.com/2a03a02a08a05/A-Further-Range-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/8a04a09a09a01a03/Knowing-Me-Knowing-God-by-Malcolm-Goldsmith.pdf
    • http://muicuiu.dumb1.com/2a07a06a03a09a06/Knowing-Me-Knowing-You-by-Mandy-Baggot.pdf
    • http://muicuiu.dumb1.com/1a05a02a02a09/Swinger-of-Birches-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/1a07a08a00a04a01/Shriek-An-Afterword-Ambergris-2-by-Jeff-VanderMeer.pdf
    • http://muicuiu.dumb1.com/8a06a05a00a00/Collected-Poems-Prose-and-Plays-by-Robert-Frost.pdf
    • http://muicuiu.dumb1.com/2a03a01a05a02/Robert-Frost-The-Years-of-Triumph-1915-1938-by-Lawrance-Thompson.pdf
    • http://muicuiu.dumb1.com/6a02a07a00a03a05/Anne-e-Patrick-Poirier-by-Anne-Poirier.pdf
    • http://muicuiu.dumb1.com/1a01a01a08a03a01a00/Knowing-the-Secret-to-Your-Inner-Self-Will-Knowing-the-Secret-Make-You-a-Better-You-by-Talitha-Barnett.pdf
    • http://muicuiu.dumb1.com/1a01a00a06a09a09a02/Heinz-Von-Foerster-1911-2002-Cybernetics-amp-Human-Knowing-Cybernetics-amp-Human-Knowing-A-Journal-of-Second-Order-Cybernetics-Auto-Poiesis-and-Cyber-Semiotics-by-Soeren-Brier.pdf
    • http://muicuiu.dumb1.com/1a08a04a07a03a07/A-Book-of-Knowing-and-Not-Knowing-A-Handbook-fo