Malicious PDF — malware analysis report

Static analysis result for SHA-256 25f81f6f0c04c1c9…

MALICIOUS

PDF

27.1 KB Created: 2019-05-07 09:13:02 +01:00 Authoring application: mPDF 5.7
MD5: 062d37050137a15e762ea8918108027c SHA-1: 936a89693915058493e96f65c290942d277a986a SHA-256: 25f81f6f0c04c1c9b0077a4f908d5ff0e440d392df1272401efd4e7ce6ef82a8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a00a08a02a03a05/What-Has-Two-Heads-Ten-Eyes-and-Terrifying-Table-Manners-An-Anthology-of-Science-Fiction-Horror-by-Sawney-Hatton.pdf
    • http://muicuiu.dumb1.com/3a00a00a01a03a09/Dead-Size-by-Sawney-Hatton.pdf
    • http://muicuiu.dumb1.com/2a09a02a00a09a00/Terrifying-Transformations-An-Anthology-of-Victorian-Werewolf-Fiction-1838-1896-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/2a04a09a05a03/Science-Fiction-Fantasy-and-Horror-1987-A-Comprehensive-Bibliography-of-Books-and-Short-Fiction-Published-in-the-English-Language-by-Charles-N-Brown.pdf
    • http://muicuiu.dumb1.com/4a00a07a07a04a09/13-An-Anthology-of-Horror-and-Dark-Fiction-by-Bradon-Nave.pdf
    • http://muicuiu.dumb1.com/4a00a07a09a09a08/13-D-j-Vu-An-Anthology-Of-Horror-And-Dark-Fiction-Thirteen-Series-Book-2-by-Bradon-Nave.pdf
    • http://muicuiu.dumb1.com/1a01a06a06a04a03a00/How-to-Write-Tales-of-Horror-Fantasy-and-Science-Fiction-by-J-N-Williamson.pdf
    • http://muicuiu.dumb1.com/4a00a08a02a02a03/The-Best-Horror-Stories-from-the-Magazine-of-Fantasy-amp-Science-Fiction-by-Edward-L-Ferman.pdf
    • http://muicuiu.dumb1.com/2a04a02a02a07/Creeping-Death-from-Neptune-Horror-and-Science-Fiction-Comics-by-Basil-Wolverton.pdf
    • http://muicuiu.dumb1.com/2a00a01a08a08a08/Genesis-An-Anthology-of-Black-Science-Fiction-by-Milton-J-Davis.pdf
    • http://muicuiu.dumb1.com/2a06a06a05a00/Before-the-Golden-Age-A-Science-Fiction-Anthology-of-the-1930s-by-Isaac-Asimov.pdf
    • http://muicuiu.dumb1.com/3a08a05a08a06/The-Gothic-Imagination-Conversations-on-Fantasy-Horror-and-Science-Fiction-in-the-Media-by-John-C-Tibbetts.pdf
    • http://muicuiu.dumb1.com/4a02a01a09a02a08/Modern-Mythmakers-35-Interviews-with-Horror-amp-Science-Fiction-Writers-and-Filmmakers-by-Michael-McCarty.pdf
    • http://muicuiu.dumb1.com/3a07a00a02a06a01/Worlds-Apart-An-anthology-of-lesbian-and-gay-science-fiction-and-fantasy-by-Camilla-Decarnin.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a00a04a03/The-Very-Best-of-Fantasy-amp-Science-Fiction-Sixtieth-Anniversary-Anthology-by-Gordon-Van-Gelder.pdf
    • http://muicuiu.dumb1.com/2a04a00a03a00a08/Walking-the-Clouds-An-Anthology-of-Indigenous-Science-Fiction-by-Grace-L-Dillon.pdf
    • http://muicuiu.dumb1.com/2a04a00a03a00a05/Terra-Nova-An-Anthology-of-Contemporary-Spanish-Science-Fiction-by-Mariano-Villarreal.pdf
    • http://muicuiu.dumb1.com/6a09a06a04a03a02/Space-Odyssey-an-Anthology-of-Great-Science-Fiction-Stories-by-Robert-Silverberg.pdf
    • http://muicuiu.dumb1.com/6a07a06a05a04a08/Hitting-the-Skids-in-Pixeltown-The-Phobos-Science-Fiction-Anthology-by-Orson-Scott-Card.pdf
    • http://muicuiu.dumb1.com/3a04a05a03a00a07/Star-Wars-on-Trial-The-Force-Awakens-Edition-Science-Fiction-and-Fantasy-Writers-Debate-the-Most-Popular-Science-Fiction-Films-of-All-Time-by-David-Brin.pdf
    • http://muicuiu.dumb1.com/2a04a09a05a03/Science-Fiction-Fantasy-and-Horror-1987-A-Compreh