Malicious PDF — malware analysis report

Static analysis result for SHA-256 8bb414c9bc63dc0f…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 03:41:52 +01:00 Authoring application: mPDF 5.7
MD5: 8ad9e7af36a27e6211702f5ad68952ec SHA-1: 965ab1fed5772af3e755b8bb3a8eb639583ab51b SHA-256: 8bb414c9bc63dc0f4276d7c56428508bf0723172516cca14b564c5cbdc5f85e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a04/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/4a04a05a03a08a05/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/3a06a05a02a04a04/The-Club-The-Club-1-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/2a06a08a00a03a04/The-Redemption-The-Club-3-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/3a06a05a09a07a09/The-Reclamation-The-Club-2-by-Lauren-Rowe.pdf
    • http://muicuiu.dumb1.com/6a08a07a07a06a03/Club-Royale-by-Lauren-Landish.pdf
    • http://muicuiu.dumb1.com/3a06a06a03a05a05/Club-Girl-Hell-Brigade-Motorcycle-Club-Book-1-by-Evelyn-Glass.pdf
    • http://muicuiu.dumb1.com/7a01a01a03a00a08/El-Club-de-Los-Suicidas-The-Suicide-Club-by-Robert-Louis-Stevenson.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a07a05a02/RIDERS-CLUB--2012-2-No-454-by-Rider-39-s-Club.pdf
    • http://muicuiu.dumb1.com/1a01a07a05a06a01a01/RIDERS-CLUB--2009-2-No-418-by-Rider-39-s-Club.pdf
    • http://muicuiu.dumb1.com/4a09a07a07a04/The-Happy-Bottom-Riding-Club-The-Life-and-Times-of-Pancho-Barnes-by-Lauren-Kessler.pdf
    • http://muicuiu.dumb1.com/7a02a05a09a04a03/Constitution-Rules-and-Regulations-of-the-Rideau-Club-Adopted-29th-August-1865-by-Rideau-Club.pdf
    • http://muicuiu.dumb1.com/9a05a00a07a09a02/2nd-Club---Verkauft-The-Club-2-by-T-C-Jayden.pdf
    • http://muicuiu.dumb1.com/8a02a05a07a01a04/THE-CUCKOLDRESS-CLUB-A-wife-love-s-her-work-as-a-Dominatrix-and-Escort-but-the-chance-to-join-The-Cuckoldress-Club-unleashes-firs-of-passion-in-her-by-Carla-Delacourt.pdf
    • http://muicuiu.dumb1.com/7a05a01a06a02a09/Kisah-Cinta-di-Curry-Club-04-Curry-Club-Ai-Ni-Kite-No-I-4-by-Kiyoko-Arai.pdf
    • http://muicuiu.dumb1.com/5a00a03a08a05a04/The-Governess-Club-Bonnie-The-Governess-Club-2-by-Ellie-Macdonald.pdf
    • http://muicuiu.dumb1.com/4a03a04a03a08a06/The-Player-s-Club-Scott-The-Player-s-Club-1-by-Cathy-Yardley.pdf
    • http://muicuiu.dumb1.com/6a07a03a09a09a07/Club-Libertine-Box-Set-Volume-1-Club-Libertine-1-2-by-Diane-Leyne.pdf
    • http://muicuiu.dumb1.com/4a07a00a08a03a06/Club-Mephisto-Club-Mephisto-1-by-Annabel-Joseph.pdf
    • http://muicuiu.dumb1.com/4a09a05a07a03a03/The-Sinners-Club-The-Sinners-Club-1-by-Kate-Pearce.pdf