Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e476f6234d7f833…

MALICIOUS

PDF

15.7 KB Created: 2019-05-03 06:08:49 +01:00 Authoring application: mPDF 5.7
MD5: 924b078f17757b7c7b367d1a992aebce SHA-1: d37600d1c7d6b8b3adc82697aa6c358704b4908d SHA-256: 3e476f6234d7f8331da31a1641a03b780a97b5dab289ffdbe74c9913465437bb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution point. While the document body itself is heavily obfuscated and unreadable, the presence of numerous links to what appear to be book-related PDFs on the domain 'muicuiu.dumb1.com' indicates a potential lure or redirection mechanism. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a02a02a07a09a04/Bram-Stoker-s-Dracula-Omnibus-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a07a00a09a02a05/Dracula-by-Bram-Stoker-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/6a03a09a00a09a00/Dracula-Illustrated-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/5a05a03a06a04a00/The-Complete-Dracula-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/1a01a08a07a00a03a04/Dracula-Bestsellers-and-famous-Books-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a02a02a07a09a07/Bram-Stoker-s-Dracula-The-Graphic-Novel-by-Gary-Reed.pdf
    • http://muicuiu.dumb1.com/7a05a01a04a05a00/Dracula-Classics-Book-All-Time-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a02a02a07a09a08/Powers-of-Darkness-The-Lost-Version-of-Dracula-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a01a06a08/Dracula-The-Most-Famous-Horror-Story-Ever-Told-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/5a05a09a01a05a04/Dracula-Illustrated-with-Photographs-of-Settings-Cultural-Artifacts-and-Vampires-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/1a06a07a00a07/Something-in-the-Blood-The-Untold-Story-of-Bram-Stoker-the-Man-Who-Wrote-Dracula-by-David-J-Skal.pdf
    • http://muicuiu.dumb1.com/2a04a06a06a08a05/Black-Shadow-Moon-Bram-Stoker-s-Dark-Secret-The-Story-of-Dracula-by-P-G-Kassel.pdf
    • http://muicuiu.dumb1.com/7a02a02a08a09a02/Black-Shadow-Moon-Bram-Stoker-s-Dark-Secret-The-Story-of-Dracula-by-P-G-Kassel.pdf
    • http://muicuiu.dumb1.com/7a02a02a08a09a06/The-Lost-Journal-of-Bram-Stoker-The-Dublin-Years-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a02a02a07a09a09/The-Lost-Novels-of-Bram-Stoker-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a02a03a00a02a03/The-Bram-Stoker-Collection-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/1a01a06a00a02a09a05/The-Watter-s-Mou-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/7a02a02a08a00a02/The-Mystery-of-the-Sea-by-Bram-Stoker.pdf
    • http://muicuiu.dumb1.com/5a09a05a00a06a06/Stoker-Day-One-by-Dracula.pdf
    • http://muicuiu.dumb1.com/7a02a02a09a07a06/Bram-Stoker-by-Andrew-Maunder.pdf
    • http://muicuiu.dumb1.com/5a05a09a01a05a04/Dracula-Illustrated-with-Photographs-of-Settings-Cultural-Artifacts-and-Vampires-by