Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a02c3abf95b6bcd…

MALICIOUS

PDF

15.7 KB Created: 2019-05-02 01:24:41 +01:00 Authoring application: mPDF 5.7
MD5: 3c9888727c67bb9b58b32f3de6ffcd88 SHA-1: 4b4b0aba8fc46ef47dfdebfdf8f47756a282129e SHA-256: 1a02c3abf95b6bcd96dc3bfa618b4bd9391cea64a9e46227410af226f8bc61a0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the document body is heavily obfuscated, the presence of numerous links to a single domain suggests a coordinated effort to drive traffic or distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.du
    • http://muicuiu.dumb1.com/4a01a04a06a01a03/Big-Easy-Temptation-The-Perfect-Gentlemen-3-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a07a01a06a01a08/Seduction-in-Session-The-Perfect-Gentlemen-2-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/5a05a02/His-to-Take-Wicked-Lovers-9-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/4a00a05a01a04a02/More-Than-Love-You-More-Than-Words-3-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/6a00a00a06a08a01/Author-Moments-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/4a08a02a04a01a06/Delicious-Wicked-Lovers-3-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a06a09a09a04a08/One-Dom-to-Love-The-Doms-of-Her-Life-1-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/2a00a04a09a01/Belong-to-Me-Wicked-Lovers-5-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/2a09a08a07a00a09/Their-Virgin-Captive-Masters-of-Menage-1-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/2a02a05a05a07a03/The-Young-and-the-Submissive-The-Doms-of-Her-Life-2-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/3a02a03a00a05a05/Falling-in-Deeper-Wicked-Lovers-11-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/3a08a06a06a03a04/Holding-on-Tighter-Wicked-Lovers-12-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a04a08a08a01a07/Strip-Search-Sexy-Capers-2-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a04a05a01a07a01/Entice-Me-at-Twilight-Doomsday-Brethren-4-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/4a08a06a01a05a08/Holding-on-Tighter-Wicked-Lovers-12-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/3a06a05a03a09a04/Tempt-Me-with-Darkness-Doomsday-Brethren-1-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/4a05a03a01a00/Wicked-Ties-Wicked-Lovers-1-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a02a02a05a05a07/Devoted-to-Pleasure-Devoted-Lovers-1-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a04a05a00a00a09/Wicked-All-the-Way-Wicked-Lovers-6-5-by-Shayla-Black.pdf
    • http://muicuiu.dumb1.com/1a00a07a05a04a05a08/Dog-Training-Made-Easy-Perfect-Puppy-Secrets-Dog-Training-Series-by-Matthew-Carcaterra.pdf