Malicious PDF — malware analysis report

Static analysis result for SHA-256 470c7775e8081d76…

MALICIOUS

PDF

21.7 KB Created: 2019-05-02 01:32:02 +01:00 Authoring application: mPDF 5.7
MD5: e05e13805ebb50fe2490b7a7cfa362ac SHA-1: 0a47f078ee1eae5fa41b25994ab4f679e77fac51 SHA-256: 470c7775e8081d7695bde08f586eaaa0f8b5c17204a3581eaa90578c0b243e6f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This pattern is indicative of a link farm or a mechanism to distribute malicious content indirectly. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a00a04a05a03a09/Fluch-der-wilden-Jahre-T-rks-zweiter-Fall-by-Robert-H-ltner.pdf
    • http://muicuiu.dumb1.com/1a00a05a00a05a03a04/Die-wilden-sechziger-Jahre-by-Roxanne-Quandt.pdf
    • http://muicuiu.dumb1.com/1a01a07a06a02a04a00/Der-bretonische-Bogensch-tze-Mary-Lesters-zweiter-Fall-by-Jean-Failler.pdf
    • http://muicuiu.dumb1.com/1a01a01a02a04a00a00/Veilchens-Feuer-Valerie-Mausers-zweiter-Fall-Alpenkrimi-by-Joe-Fischler.pdf
    • http://muicuiu.dumb1.com/9a04a06a07a05a08/K-hl-bis-ans-Herz-Sailer-und-Schatz-ihr-zweiter-Fall---Frankenkrimi-by-Sigrun-Arenz.pdf
    • http://muicuiu.dumb1.com/9a08a07a02a02a00/Zweiter-Weltkrieg-Erlebnisbericht-vom-erfolgreichen-Blitzkrieg-im-Westfeldzug-bis-zu-schwersten-Abwehrschlachten-an-der-Ostfront-Fall-Gelb---Barbarossa---Unternehmen-Zitadelle-by-Walter-M-nch.pdf
    • http://muicuiu.dumb1.com/1a01a01a02a03a00a08/Auf-die-feine-Art-Maria-Kallios-zweiter-Fall-Maria-Kallio-ermittelt-2-by-Leena-Lehtolainen.pdf
    • http://muicuiu.dumb1.com/1a00a06a00a07a08a01/Faust-Zweiter-Teil-Der-Trag-die-zweiter-Teil-in-f-nf-Akten-by-Johann-Wolfgang-von-Goethe.pdf
    • http://muicuiu.dumb1.com/8a08a08a00a05a05/Rotk-ppchen-in-Jahre-1999-by-Robert-Krauss.pdf
    • http://muicuiu.dumb1.com/9a00a05a04a03a02/Der-Drogenkrieg-in-Den-Anden-Von-Den-Anfangen-Bis-in-Die-1990er-Jahre-by-Robert-Lessmann.pdf
    • http://muicuiu.dumb1.com/8a08a01a06a07a05/Ernst-J-nger-und-sein-Kriegstagebuch-quot-In-Stahlgewittern-quot---eine-Untersuchung-der-verschiedenen-Fassungen-vor-dem-Hintergrund-der-Jahre-1919-1934-by-Robert-Hanulak.pdf
    • http://muicuiu.dumb1.com/5a06a08a06a05/The-Fall-of-a-Sparrow-by-Robert-Hellenga.pdf
    • http://muicuiu.dumb1.com/1a05a04a08a04a04/The-Fall-The-Rift-1-by-Robert-J-Duperre.pdf
    • http://muicuiu.dumb1.com/4a07a09a08a09a07/The-Fall-of-Princes-by-Robert-Goolrick.pdf
    • http://muicuiu.dumb1.com/1a07a01a05a04/Free-Fall-Elvis-Cole-4-by-Robert-Crais.pdf
    • http://muicuiu.dumb1.com/6a02a03a09a04a06/The-Rise-and-Fall-of-Napoleon-Bonaparte-by-Robert-B-Asprey.pdf
    • http://muicuiu.dumb1.com/4a04a03a01a08a02/The-Eleven-Hour-Fall-The-Eleven-Hour-Fall-1-by-Robert-Appleton.pdf
    • http://muicuiu.dumb1.com/3a09a07a09a01a09/Kate-of-Kratos-The-Eleven-Hour-Fall-3-by-Robert-Appleton.pdf
    • http://muicuiu.dumb1.com/2a05a04a09a02a01/Bourgeois-Utopias-The-Rise-And-Fall-Of-Suburbia-by-Robert-Fishman.pdf
    • http://muicuiu.dumb1.com/3a03a09a02a02a05/House-of-Treason-The-Rise-and-Fall-of-a-Tudor-Dynasty-by-Robert-Hutchinson.pdf
    • http://muicuiu.dumb1.com/9a08a07a02a02a00/Zweiter-Weltkrieg-Erlebnisbericht-vom-erfolgreichen-Blitzkrieg-im-Westfeldzug-bis-zu-schwersten-Abwehrschlachten-an-der-Ostfront-F