Malicious PDF — malware analysis report

Static analysis result for SHA-256 f887e27c5e56949f…

MALICIOUS

PDF

17.4 KB Created: 2019-05-08 13:49:45 +01:00 Authoring application: mPDF 5.7
MD5: 5ab6e87cf364413eb8c78713abae427f SHA-1: 627f7149dd274fb86f9a77444cb58cef5a5aa0a2 SHA-256: f887e27c5e56949f6159ea97388a7d92bc6959914afa974450eee109ef257c1a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to serve as a landing page for further malicious activity. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a01a09a01a02a07/The-Room-in-the-Dragon-Volant-by-J-Sheridan-Lefanu-Fiction-Horror-by-J-Sheridan-Le-Fanu.pdf
    • http://muicuiu.dumb1.com/1a08a06a09a09a04/Words-Words-Words-by-David-Crystal.pdf
    • http://muicuiu.dumb1.com/1a01a03a02a08a09a01/The-Archie-Sheridan-and-Gretchen-Lowell-Series-Archie-Sheridan-amp-Gretchen-Lowell-1-3-by-Chelsea-Cain.pdf
    • http://muicuiu.dumb1.com/1a00a02a08a06a08a04/Words-and-the-Mind-How-Words-Capture-Human-Experience-by-Barbara-Malt.pdf
    • http://muicuiu.dumb1.com/2a07a02a04a06a03/Words-Under-the-Words-Selected-Poems-by-Naomi-Shihab-Nye.pdf
    • http://muicuiu.dumb1.com/1a04a07a05a07a07/The-Truest-of-Words-Words-3-by-Georgina-Guthrie.pdf
    • http://muicuiu.dumb1.com/6a05a08a09a06a06/-quot-War-of-Words-and-Tumult-of-Opinions-quot-The-Battle-for-Joseph-Smith-s-Words-in-Book-of-Mormon-Geography-Interpreter-A-Journal-of-Mormon-Scripture-11-by-Neal-Rappleye.pdf
    • http://muicuiu.dumb1.com/8a09a03a02a06/Leo-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/7a05a08a06a01/Three-Words-Eight-Letters-Say-It-and-I-m-Yours-Three-Words-Eight-Letters-Say-It-and-I-m-Yours-1-by-Jade-Margarette-Pitogo.pdf
    • http://muicuiu.dumb1.com/3a09a04a02a04/Stinger-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/4a04a00a08/Archer-s-Voice-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/2a05a01a02a09a09/Carmilla-by-J-Sheridan-Le-Fanu.pdf
    • http://muicuiu.dumb1.com/2a04a02a04a09a08/Dane-s-Storm-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/4a01a03a04a08/Finding-Eden-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/6a03a01a06a06/Zoology-by-Sheridan-Keith.pdf
    • http://muicuiu.dumb1.com/4a08a02a09a03a08/Carmilla-by-J-Sheridan-Le-Fanu.pdf
    • http://muicuiu.dumb1.com/3a06a08a08a07a02/Archer-s-Voice-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/2a04a02a09a01a00/Dane-s-Storm-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/2a08a04a06/Midnight-Lily-by-Mia-Sheridan.pdf
    • http://muicuiu.dumb1.com/9a02a07a09a09a04/Queen-Bertha-or-The-vow-by-C-Montucci-Sheridan.pdf
    • http://muicuiu.dumb1.com/6a05a08a09a06a06/-quot-War-of-Words-