Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c74ef40220268fe…

MALICIOUS

PDF

23.7 KB Created: 2019-04-30 03:53:51 +01:00 Authoring application: mPDF 5.7
MD5: c0f2f3642fd071311e1129497d2f37b7 SHA-1: a14f523437aee35b0ad514cf0b7965408bfad3a6 SHA-256: 4c74ef40220268fe939f8ca4d1fefb94ac9cb2162f47961e1a0b13120f2e0232
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of external links, many of which are dynamically generated and point to a suspicious domain. This indicates a likely attempt to lure users to potentially harmful content, possibly for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a01a00a07a09a06/Der-Sohn-des-F-rsten-by-Logan-Redwood.pdf
    • http://muicuiu.dumb1.com/4a03a01a04a02a06/Under-the-Redwood-Tree-Redwood-Coast-1-by-Elizabeth-Goddard.pdf
    • http://muicuiu.dumb1.com/1a00a07a04a02a06a00/Briefwechsel-Christian-F-rchtegott-Gellert-s-Mit-Demoiselle-Lucius-Nebst-Einem-Anhange-Enthaltend-1-Eine-Rede-Gellert-s-Gehalten-VOR-Dem-Churf-rsten-in-Leipzig-2-Ein-Gedicht-Gellert-s-an-Den-Churf-rsten-3-Ein-Brief-Rabener-s-an-Gellert-Und-Dess-by-Friedrich-Adolf-Ebert.pdf
    • http://muicuiu.dumb1.com/2a04a08a09a08a03/Redwood-Pack-Vol-5-Redwood-Pack-6-6-5-by-Carrie-Ann-Ryan.pdf
    • http://muicuiu.dumb1.com/1a01a07a09a01a03a00/Briefe-Eines-Dollar-Koenigs-an-Seinen-Sohn-Diese-Briefe-Schrieb-Der-Chef-Der-Schweinefleisch-Versand-Grosshandlung-Graham-amp-Co-in-Chicago-Herr-John-Graham-an-Der-Boerse-Unter-Dem-Spitznamen-der-Alte-Schweine-Graham-Bekannt-and-Seinen-Sohn-Pierrepon-by-George-Horace-Lorimer.pdf
    • http://muicuiu.dumb1.com/9a03a04a00a04/Logan-s-Run-Logan-1-by-William-F-Nolan.pdf
    • http://muicuiu.dumb1.com/1a00a02a06a02a02a09/Die-V-lker-Spaniens-Und-Ihre-F-rsten-Ein-Historisch-Statistisch-Geographisches-Denkbuch-F-r-Gebildete-In-Zwei-Abtheilungen-by-Heinrich-Seel.pdf
    • http://muicuiu.dumb1.com/3a09a07a06a05a06/Prospect-Park-West-by-Amy-Sohn.pdf
    • http://muicuiu.dumb1.com/1a00a02a05a02a00a09/MUTTERGL-CK---Hommage-an-meinen-Sohn-by-Mitzi-Mog.pdf
    • http://muicuiu.dumb1.com/9a01a01a05a05a09/Der-Sohn-meines-Feindes-by-France-Carol.pdf
    • http://muicuiu.dumb1.com/8a09a05a07a00a05/Der-perfekte-Sohn-by-Barbara-Claypole-White.pdf
    • http://muicuiu.dumb1.com/4a00a04a00a04a00/The-Redwood-Revenger-by-Johannes-Johns.pdf
    • http://muicuiu.dumb1.com/1a00a05a08a00a07/Redwood-and-Wildfire-by-Andrea-Hairston.pdf
    • http://muicuiu.dumb1.com/2a00a07a03a09a05/Forgiveness-Redwood-Pack-3-7-by-Carrie-Ann-Ryan.pdf
    • http://muicuiu.dumb1.com/1a00a08a03a01a04a04/Das-Kirchenhasser-Brevier-Ein-verlorener-Sohn-rechnet-ab-by-Ulli-Schauen.pdf
    • http://muicuiu.dumb1.com/2a08a01a03a01a05/A-Beta-s-Haven-Redwood-Pack-5-5-by-Carrie-Ann-Ryan.pdf
    • http://muicuiu.dumb1.com/2a00a05a08a09a07/Shattered-Emotions-Redwood-Pack-4-by-Carrie-Ann-Ryan.pdf
    • http://muicuiu.dumb1.com/1a07a08a05a03a01/Redwood-Bend-Virgin-River-16-by-Robyn-Carr.pdf
    • http://muicuiu.dumb1.com/3a09a07a01a00a09/Redwood-Bend-Virgin-River-16-by-Robyn-Carr.pdf
    • http://muicuiu.dumb1.com/5a00a05a09a04a07/A-Taste-for-a-Mate-Redwood-Pack-1-by-Carrie-Ann-Ryan.pdf
    • http://muicuiu.dumb1.com/1a01a07a09a01a03a00/Briefe-Eines-Dollar-Koenig