Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d1fd04f91d1367d…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 04:13:13 +01:00 Authoring application: mPDF 5.7
MD5: 167e9cb294a64d68e017134d0b6dfa1d SHA-1: 3c3b7264ccac201d2ab67c87a9136ebee42fe530 SHA-256: 1d1fd04f91d1367dffc99b5bfb5d36b5b53f7c83e9e4159d97100509fc7c8db6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'muicuiu.dumb1.com'. This pattern is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a09a06a01a07/The-Color-Between-Black-and-White-by-S-C-Russell.pdf
    • http://muicuiu.dumb1.com/3a02a08a06a04/The-Color-of-Water-A-Black-Man-s-Tribute-to-His-White-Mother-by-James-McBride.pdf
    • http://muicuiu.dumb1.com/4a00a08a08a01a03/The-Color-of-Water-A-Black-Man-s-Tribute-to-His-White-Mother-by-James-McBride.pdf
    • http://muicuiu.dumb1.com/1a01a00a04a03a04a05/Black-White-and-in-Color-Essays-on-American-Literature-and-Culture-by-Hortense-Spillers.pdf
    • http://muicuiu.dumb1.com/8a02a09a01a02a09/Mastering-Digital-Black-and-White-A-Photographer-s-Guide-to-High-Quality-Black-And-White-Imaging-and-Printing-by-Amadou-Diallo.pdf
    • http://muicuiu.dumb1.com/5a09a07a07a02/The-Color-Purple-Piano-Vocal-Selections-by-Brenda-Russell.pdf
    • http://muicuiu.dumb1.com/4a05a00a09a00/Where-White-Men-Fear-to-Tread-The-Autobiography-of-Russell-Means-by-Russell-Means.pdf
    • http://muicuiu.dumb1.com/4a01a05a07a06a01/Christians-and-the-Color-Line-Race-and-Religion-After-Divided-by-Faith-by-J-Russell-Hawkins.pdf
    • http://muicuiu.dumb1.com/3a00a04a02a05a05/The-Color-of-Light-by-Karen-White.pdf
    • http://muicuiu.dumb1.com/9a07a08a01a01a09/White-Is-a-Color-by-Rosmarie-Waldrop.pdf
    • http://muicuiu.dumb1.com/2a00a07a04a03/The-Color-of-Light-by-Karen-White.pdf
    • http://muicuiu.dumb1.com/3a02a09a04a05a04/White-Is-the-Color-of-Death-by-Margaret-Killjoy.pdf
    • http://muicuiu.dumb1.com/2a03a09a04a05/Batman-Black-and-White-Batman-Black-and-White-1-by-Mark-Chiarello.pdf
    • http://muicuiu.dumb1.com/2a01a06a08a01a09/White-Women-The-Sex-Black-Men-Love-Why-White-Women-Is-the-Choice-for-Cheating-Black-Men-by-Raymoni-Love.pdf
    • http://muicuiu.dumb1.com/4a08a09a00a09a01/Black-Berry-Sweet-Juice-On-Being-Black-and-White-in-Canada-by-Lawrence-Hill.pdf
    • http://muicuiu.dumb1.com/3a00a02a01a07a02/White-on-Black-on-White-by-Coleman-Dowell.pdf
    • http://muicuiu.dumb1.com/2a03a08a02a07a05/Black-The-History-of-a-Color-by-Michel-Pastoureau.pdf
    • http://muicuiu.dumb1.com/5a06a01a02a06a04/Black-is-Not-a-Color-The-Ava-Series-2-by-Rozsa-Gaston.pdf
    • http://muicuiu.dumb1.com/2a06a02a01a06a05/Black-In-White-Quentin-Black-Mystery-1-by-J-C-Andrijeski.pdf
    • http://muicuiu.dumb1.com/6a08a09a06a08a00/Exploring-Race-in-Predominantly-White-Classrooms-Scholars-of-Color-Reflect-by-George-Yancy.pdf
    • http://muicuiu.dumb1.com/5a09a07a07a02/The-Color-Purple-Piano-Vocal-Selecti