Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff7bc0ce08b26976…

MALICIOUS

PDF

19.8 KB Created: 2019-05-06 16:54:13 +01:00 Authoring application: mPDF 5.7
MD5: 651ac87847fe2e68d9216052143ce9ac SHA-1: 5d5d902e21e14748b4cd1ffb7f3e48073be50eba SHA-256: ff7bc0ce08b269762c1f1e264d17d9fb9ba91a89d8d4952b1b4d663ea783492f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the document body contains numerous URLs pointing to external content, suggesting a link-farming or redirection scheme. The primary goal appears to be directing users to a multitude of external websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a06a09a00a04a01/Jerome-K-Jerome-Collected-Works-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a06a09a00a04a06/Humorous-World-of-Jerome-K-Jerome-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/9a03a00a09a06a05/Drei-Mann-in-einem-Boot-vom-Hunde-ganz-zu-schweigen-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/8a06a05a04a03a06/Drei-Mann-in-einem-Boot-Ganz-zu-schweigen-vom-Hund-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/6a00a01a05a06a08/Three-Men-in-a-Boat-To-Say-Nothing-of-the-Dog-New-Illustrated-Edition-with-67-Original-Drawings-by-A-Frederics-a-Detailed-Map-of-Tour-and-a-Photo-of-the-Three-Men-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a05a04a01a04a05/Tres-hombres-en-una-barca-por-no-mencionar-al-perro-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/7a03a02a04a04a04/The-Soul-of-Nicholas-Snyders-Or-the-Miser-of-Zandam-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a02a07a00a05a00/Trois-hommes-dans-un-bateau-Annot-Livre-bilingue-Apprendre-l-anglais-en-lisant-Book-18-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/1a01a02a06a06a05a00/Three-Men-in-a-Boat-To-Say-Nothing-of-the-Dog-Illustrated-1889-edition-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/6a02a09a05a03a04/Trois-hommes-dans-un-bateau-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a02a08a08a00a01/Trois-Hommes-Dans-Un-Bateau-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a06a09a00a03a00/Second-Thoughts-Of-An-Idle-Fellow-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/8a02a02a03a08a03/Idle-Thoughts-of-an-Idle-Fellow-A-Humourous-Take-on-Mundane-Topics-Aziloth-Books-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/1a00a09a01a04a04a02/Tre-uomini-in-barca-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/4a06a09a06a08a00/Three-Men-in-a-Boat-To-Say-Nothing-of-the-Dog-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/4a04a00a01a09a03/Three-Men-in-a-Boat-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/7a02a07a03a02/Three-Men-In-A-Boat-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/9a09a03a07a03a03/Tommy-amp-Co-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a09a08a04a07a00/Three-Men-in-a-Boat-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/7a00a02a00a03a04/Into-the-Light-The-Photography-of-J-r-me-Brunet-by-J-r-me-Brunet.pdf
    • http://muicuiu.dumb1.com/5a05a04a01a04a05