Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ed52cdd81cb2cd3…

MALICIOUS

PDF

25.0 KB Created: 2019-05-02 11:12:42 +01:00 Authoring application: mPDF 5.7
MD5: 132ca01bd8af2488022c071856ac34f2 SHA-1: 2efa1b723fdc3e2f2c251f249aefe4be6238cf84 SHA-256: 7ed52cdd81cb2cd324b2a1733a5a68a71501697a3e774b1efde60c25e582bbef
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This domain and the structure of the links suggest a link farm or SEO poisoning tactic, likely intended to drive traffic or distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a09a00a08a09a05/Works-and-Days-Theogony-by-Hesiod.pdf
    • http://muicuiu.dumb1.com/5a09a06a07a04a06/Teogonija-Dela-in-dnevi-by-Hesiod.pdf
    • http://muicuiu.dumb1.com/1a09a00a05a04a04/The-Shield-Catalogue-of-Women-Other-Fragments-by-Hesiod.pdf
    • http://muicuiu.dumb1.com/9a05a06a09a03a01/Plato-and-Hesiod-by-George-Boys-Stones.pdf
    • http://muicuiu.dumb1.com/1a01a02a00a06a09a06/Pulitzer-Prize-Winning-Works-Collections-11-Works-One-of-Ours-Alice-Adams-Anna-Christie-Miss-Lulu-Bett-by-Willa-Cather.pdf
    • http://muicuiu.dumb1.com/4a05a02a03a00a05/Eleven-Days-An-Unexpected-Love-Days-Trilogy-1-by-Lora-Lindy.pdf
    • http://muicuiu.dumb1.com/7a08a02a08a03a08/School-Days-and-Steam-Days-The-Trainspotting-Adventures-of-Paul-Carr-by-Barry-Allen.pdf
    • http://muicuiu.dumb1.com/7a05a01a01a09a03/Works-of-Voltaire-20-works-Candide-Zadig-Philosophical-Dictionary-selected-poetry-amp-more-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/4a02a01a06a05a09/23-Days-A-short-memoir-of-a-former-police-officer-s-life-from-childhood-dreams-to-his-calling-to-his-last-23-days-that-changed-it-all-by-Ty-Gray.pdf
    • http://muicuiu.dumb1.com/1a00a00a00a04a09a06/An-Introduction-Prose-and-Poetical-Works-of-John-Milton-Comprising-All-the-Autobiographic-Passages-in-His-Works-the-More-Explicit-Presentations-of-His-Ideas-of-True-Liberty-Comus-Lycidas-and-Samson-Agonistes-with-Notes-and-Forewords-by-Hiram-Corson.pdf
    • http://muicuiu.dumb1.com/8a04a06a00a00a03/The-Second-Angela-Brazil-s-Collected-Works-The-Princess-of-the-School-A-Fortunate-Term-and-More-12-Works-The-Schoolgirl-s-Sories-by-Angela-Brazil.pdf
    • http://muicuiu.dumb1.com/1a00a00a00a05a04a05/An-introduction-to-the-prose-and-poetical-works-of-John-Milton-comprising-all-the-autobiographic-passages-in-his-works-the-more-explicit-presentations-of-his-ideas-of-true-liberty-Comus-Lycidas-and-Samson-Agonistes-with-notes-and-forewords-by-John-Milton.pdf
    • http://muicuiu.dumb1.com/1a07a05a02a09a08/738-Days-738-Days-1-by-Stacey-Kade.pdf
    • http://muicuiu.dumb1.com/2a01a08a03a06a00/Dog-Days-Dog-Days-1-by-John-Levitt.pdf
    • http://muicuiu.dumb1.com/4a07a02a08a06/End-of-Days-Penryn-amp-the-End-of-Days-3-by-Susan-Ee.pdf
    • http://muicuiu.dumb1.com/1a00a08a05a08a00/In-27-Days-In-27-Days-1-by-Alison-Gervais.pdf
    • http://muicuiu.dumb1.com/8a01a06/End-of-Days-Penryn-amp-the-End-of-Days-3-by-Susan-Ee.pdf
    • http://muicuiu.dumb1.com/4a06a02a00a00a08/31-Days-of-Summer-31-Days-2-by-C-J-Fallowfield.pdf
    • http://muicuiu.dumb1.com/4a06a02a00a00a09/31-Days-of-Winter-31-Days-1-by-C-J-Fallowfield.pdf
    • http://muicuiu.dumb1.com/9a02a07a00a07a06/Thirty-Days-Have-November-Thirty-Days-2-by-Bibi-Paterson.pdf