Malicious PDF — malware analysis report

Static analysis result for SHA-256 1baee9ca531b5df5…

MALICIOUS

PDF

27.6 KB Created: 2019-05-02 00:59:24 +01:00 Authoring application: mPDF 5.7
MD5: 10655b4d8648fc73fdc01af894fbc5af SHA-1: 2197b7c4ca2fbe57c4b199fd01ec2d8c12c0fb5c SHA-256: 1baee9ca531b5df554778c97d76f056c35f1c5ebcfa3d1355328a615e602e022
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a06a02a09a05a03/Aunt-Tilda-by-Deborah-McClatchey.pdf
    • http://muicuiu.dumb1.com/1a02a08a06a08a08/Tuning-in-to-Terror-by-Deborah-McClatchey.pdf
    • http://muicuiu.dumb1.com/2a09a01a07a06a00/Fallen-Angels-by-Deborah-McClatchey.pdf
    • http://muicuiu.dumb1.com/3a07a07a02a08a05/Time-Out-of-Joint-by-Philip-K-Dick.pdf
    • http://muicuiu.dumb1.com/6a07a05a01a07a05/Joint-Operations-Carrier-16-by-Keith-Douglass.pdf
    • http://muicuiu.dumb1.com/6a07a08a07a03a03/That-s-the-Joint-The-Hip-Hop-Studies-Reader-by-Murray-Forman.pdf
    • http://muicuiu.dumb1.com/4a07a00a04a07a04/Joint-Enterprise-The-Romney-and-Marsh-Files-3-by-Oliver-Tidy.pdf
    • http://muicuiu.dumb1.com/2a06a06a04a01a01/Destroying-the-Joint-Why-Women-Have-to-Change-the-World-by-Jane-Caro.pdf
    • http://muicuiu.dumb1.com/1a00a08a03a03a04a08/Shadow-of-Night-by-Deborah-Harkness-Unabridged-MP3-CD-Audiobook-All-Souls-Trilogy-Book-2-by-Deborah-Harkness.pdf
    • http://muicuiu.dumb1.com/7a07a00a08a00a00/Sicily-1943-The-debut-of-Allied-joint-operations-by-Steven-J-Zaloga.pdf
    • http://muicuiu.dumb1.com/7a09a04a03a00a00/The-Intellectual-Revolution-Selections-from-Euripides-Thucydides-and-Plato-by-Joint-Association-of-Classical-Teachers.pdf
    • http://muicuiu.dumb1.com/6a04a07a01a02a06/The-Early-History-of-Financial-Economics-1478-1776-From-Commercial-Arithmetic-to-Life-Annuities-and-Joint-Stocks-by-Geoffrey-Poitras.pdf
    • http://muicuiu.dumb1.com/8a03a04a03a02a05/Si-cle-de-Louis-XIV-Vol-1-Auquel-on-a-Joint-Un-Pr-cis-Du-Si-cle-de-Louis-XV-Et-Un-Autre-Morceau-D-Histoire-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/1a00a05a04a04a00a01/Summary-of-the-Tax-Reform-Act-of-1976-H-R-10612-94th-Congress-Public-Law-94-455-by-U-S-Congress-Joint-Committee-on-Taxation.pdf
    • http://muicuiu.dumb1.com/7a03a09a09a01a05/Manual-Mobilization-of-the-Joints-The-Kaltenborn-Method-of-Joint-Examination-and-Treatment-The-Extremities-by-Freddy-M-Kaltenborn.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a06a07a05/Joint-Venture-The-Venture-Series-Book-4-by-Kristen-Luciani.pdf
    • http://muicuiu.dumb1.com/9a01a02a03a01a05/History-Out-of-Joint-Essays-on-the-Use-and-Abuse-of-History-by-Sande-Cohen.pdf
    • http://muicuiu.dumb1.com/1a00a08a02a01a04a00/Three-Dimensional-Magnetic-Resonance-Imaging-An-Integrated-Clinical-Up-Date-of-3D-Imaging-and-3D-Postprocessing-Proceedings-of-a-Joint-Meeting-in-by-F-Aichner.pdf
    • http://muicuiu.dumb1.com/7a07a02a01a07a03/Forging-Nonprofit-Alliances-A-Comprehensive-Guide-to-Enhancing-Your-Mission-Through-Joint-Ventures-amp-Partnerships-Management-Service-Organizations-Parent-Corporations-and-Mergers-by-Jane-Arsenault.pdf
    • http://muicuiu.dumb1.com/7a08a07a06a01a03/Ra-c-Flexions-Sentences-Et-Maximes-Morales-de-La-Rochefoucauld-Nouvelle-A-c-Dition-Conforme-a-Celle-de-1678-Et-a-Laquelle-on-Joint-Les-Annotations-D-Un-Contemporain-by-Fran-ois-de-La-Rochefoucauld.pdf
    • http://muicuiu.dumb1.com/7a07a00a08a00a00/Sicily-1943-The-debut-of-Allied-joint-operations-by-St