Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a1cfd8a329f4eac…

MALICIOUS

PDF

19.4 KB Created: 2019-05-02 10:36:20 +01:00 Authoring application: mPDF 5.7
MD5: 8432ef073b1046f155cd1edd85292461 SHA-1: 77716e27e2bccceae580c1105ef4d7488a69c5da SHA-256: 3a1cfd8a329f4eac58f7c5946d42a37d551866620b3e0495f1dbec58e5c097ae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to various websites. While the majority of these URLs were labeled as confirmed benign, the sheer volume and the ML_NYX_PDF_MALICIOUS classification indicate a malicious intent, likely to drive traffic or potentially host malicious content on a subset of these domains. The document body was unreadable, preventing a more specific assessment of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dum
    • http://muicuiu.dumb1.com/1a00a08a03a05a00a03/The-Anxiety-Journal-Exercises-to-soothe-stress-and-eliminate-anxiety-wherever-you-are-by-Corinne-Sweet.pdf
    • http://muicuiu.dumb1.com/6a00a02a06a03a07/Anxiety-and-Avoidance-A-Universal-Treatment-for-Anxiety-Panic-and-Fear-by-Michael-A-Tompkins.pdf
    • http://muicuiu.dumb1.com/9a09a03a03a02a09/Anxiety-How-To-Take-Charge-Of-Your-Life-And-End-Your-Daily-Struggle-With-Anxiety-by-Sarah-Riedel.pdf
    • http://muicuiu.dumb1.com/9a05a09a02a04a02/The-Anxiety-Code-Deciphering-the-Purposes-of-Neurotic-Anxiety-by-Roger-Di-Pietro.pdf
    • http://muicuiu.dumb1.com/3a02a02a00a09a00/Anxiety-Cure-Scientifically-Proven-Ways-to-Reduce-Anxiety-Symptoms-by-Marie-Cheour.pdf
    • http://muicuiu.dumb1.com/2a05a03a09a09a09/The-Social-Anxiety-amp-Shyness-Cure-The-Secret-to-Overcoming-Social-Anxiety-and-Gaining-Confidence-by-Scott-Cooper.pdf
    • http://muicuiu.dumb1.com/4a06a01a00a07a03/Understanding-and-Overcoming-Anxiety-and-Panic-Attacks-a-Guide-for-You-and-Your-Caregiver-How-to-Stop-Anxiety-Stress-Panic-Attacks-Phobia-amp-Agoraphobia-Now-by-Julie-Stevenson.pdf
    • http://muicuiu.dumb1.com/9a00a08a06a08a01/Nightfall-by-Moshe-Ben-Or.pdf
    • http://muicuiu.dumb1.com/4a01a09a07a02a06/Moshe-Dayan-by-Moshe-Dayan.pdf
    • http://muicuiu.dumb1.com/7a02a01a05a07a06/The-Moshe-Lifestyle-by-Tyler-Wilkinson.pdf
    • http://muicuiu.dumb1.com/7a01a00a04a07a07/The-Diamond-Setter-by-Moshe-Sakal.pdf
    • http://muicuiu.dumb1.com/1a00a04a00a01a02a09/The-Complete-Mezuzah-Guide-by-Moshe-Elefant.pdf
    • http://muicuiu.dumb1.com/7a03a08a00a00a00/Aphorisms-and-Quotations-for-the-Surgeon-by-Moshe-Schein.pdf
    • http://muicuiu.dumb1.com/6a01a09a06a02/Studies-in-Ecstatic-Kabbalah-by-Moshe-Idel.pdf
    • http://muicuiu.dumb1.com/1a01a05a00a09a06/Ben-Sonship-and-Jewish-Mysticism-by-Moshe-Idel.pdf
    • http://muicuiu.dumb1.com/7a02a01a05a09a04/The-Potent-Self-A-Guide-to-Spontaneity-by-Mosh-Feldenkrais.pdf
    • http://muicuiu.dumb1.com/7a02a03a01a09a08/Queues-A-Course-in-Queueing-Theory-by-Moshe-Haviv.pdf
    • http://muicuiu.dumb1.com/1a00a05a08a00a02/Haven-of-Dante-The-Staff-of-Moshe-by-Leonardo-Ramirez.pdf
    • http://muicuiu.dumb1.com/6a04a01a08a08/The-Mystical-Experience-in-Abraham-Abulafia-by-Moshe-Idel.pdf
    • http://muicuiu.dumb1.com/7a00a04a09a07a06/Haven-of-Dante-The-Staff-of-Moshe-by-Leonardo-Ramirez.pdf