Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f20d069d30b3c1c…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 06:15:58 +01:00 Authoring application: mPDF 5.7
MD5: 412cb46588151d0a616d7dc6a1200af9 SHA-1: 29c9f3cc8436e10cc641687fd94d8c73a6009541 SHA-256: 1f20d069d30b3c1c0ef9ef005b61df14e57c39fd5ab4a3efa2dabbc65df7b2e5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the `muicuiu.dumb1.com` domain. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a deliberate attempt at SEO poisoning or driving traffic to a malicious infrastructure. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a06a05a04a06/The-After-Girls-by-Leah-Konen.pdf
    • http://muicuiu.dumb1.com/4a04a04a04/The-Romantics-by-Leah-Konen.pdf
    • http://muicuiu.dumb1.com/1a05a09a00a09a05/Love-and-Other-Train-Wrecks-by-Leah-Konen.pdf
    • http://muicuiu.dumb1.com/1a00a00a09a01a04a07/The-Romantics-oder-wie-Gael-das-mit-der-Liebe-lernte-by-Leah-Konen.pdf
    • http://muicuiu.dumb1.com/5a00a01a01a06a00/Winters-Rising-Lexcon-Time-Travel-1-by-Shannyn-Leah.pdf
    • http://muicuiu.dumb1.com/2a03a02a02a06a04/Prophecy-Alchemy-and-the-End-of-Time-John-of-Rupescissa-in-the-Late-Middle-Ages-by-Leah-DeVun.pdf
    • http://muicuiu.dumb1.com/2a01a09a01a05/Time-s-Arrow-Time-s-Cycle-Myth-and-Metaphor-in-the-Discovery-of-Geological-Time-by-Stephen-Jay-Gould.pdf
    • http://muicuiu.dumb1.com/2a00a03a04a09a07/TIME-TRAVEL-EXPERIENCES-In-a-Sense-we-all-are-Time-Travelers-We-are-surviving-each-and-every-Active-Time-Point-in-this-Timeline-by-Aldrin-Mathew.pdf
    • http://muicuiu.dumb1.com/4a04a05a08a09a02/The-Big-Book-Of-Time-Travel-Romance-Includes-After-Cilmeri-0-5-Lost-Highlander-1-The-McKinnon-Legends-1-Out-of-Time-1-Time-Walkers-1-by-Sarah-Woodbury.pdf
    • http://muicuiu.dumb1.com/3a02a01a09a08a08/Three-in-Time-The-Winds-of-Time-The-Year-of-the-Quiet-Sun-There-Will-Be-Time-by-Chad-Oliver.pdf
    • http://muicuiu.dumb1.com/1a04a08a03a08a07/Unteachable-by-Leah-Raeder.pdf
    • http://muicuiu.dumb1.com/3a05a05a06a06a03/Alpha-On-Top-by-Leah-Holt.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a07a06a02/Leah-by-Dana-K-Haffar.pdf
    • http://muicuiu.dumb1.com/5a01a02a01a00a06/Leah-by-Seymour-Epstein.pdf
    • http://muicuiu.dumb1.com/1a08a02a07a00a07/The-History-of-Us-by-Leah-Stewart.pdf
    • http://muicuiu.dumb1.com/2a07a06a01a03a05/The-Postcard-by-Leah-Fleming.pdf
    • http://muicuiu.dumb1.com/2a06a00a06a06a08/The-History-of-Us-by-Leah-Stewart.pdf
    • http://muicuiu.dumb1.com/2a09a00a06a02a07/A-Question-of-Counsel-by-Archer-Kay-Leah.pdf
    • http://muicuiu.dumb1.com/1a05a01a04a06a09/Losing-Leah-by-Tiffany-King.pdf
    • http://muicuiu.dumb1.com/7a02a08a04a05a04/Conte-du-l-zard-vert-by-Leah.pdf
    • http://muicuiu.dumb1.com/2a00a03a04a09a07/TIME-TRAVEL-EXPERIENCES-In-a-Sense-we-all-are-Time-Trave