Malicious PDF — malware analysis report

Static analysis result for SHA-256 97b19a56e4246014…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 04:58:07 +01:00 Authoring application: mPDF 5.7
MD5: a1b0f6f04117516e2156a7187cb2d709 SHA-1: ee87e7c79b451b29ec5c6c97528ecb08f875fd85 SHA-256: 97b19a56e42460142cb610c9198829de61e22dd73ab2185164bf8e40a9b6bc1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of links to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a04a00a02a02/Any-Human-Heart-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/3a07a00a08a01a01/Any-Human-Heart-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/7a03a01a06a01a07/Varieties-of-Religious-Experience-A-Study-of-Human-Nature-Human-Immortality-Two-Supposed-Objections-to-the-Doctrine-by-William-James.pdf
    • http://muicuiu.dumb1.com/4a05a04a05a00a03/Solo-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/4a04a01a07a04/The-Blue-Afternoon-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/6a01a07a03a01/A-Good-Man-in-Africa-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/2a05a02a05a03a02/Love-is-Blind-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/4a00a04a05a04/Brazzaville-Beach-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/8a03a08a03a07/Stars-and-Bars-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/4a05a02a04a04a06/Brazzaville-Beach-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/1a01a03a05a03a07a08/Unser-Mann-in-Afrika-by-William-Boyd.pdf
    • http://muicuiu.dumb1.com/7a09a00a04a05a06/Four-Letters-of-Comforts-for-the-Deaths-of-the-Earle-of-Hadingtoun-and-of-the-Lord-Boyd-1640-by-Zacharie-Boyd.pdf
    • http://muicuiu.dumb1.com/7a09a00a04a05a05/Selected-Sermons-of-Zachary-Boyd-by-Zacharie-Boyd.pdf
    • http://muicuiu.dumb1.com/7a01a02a03a08/In-the-Heart-of-the-Heart-of-the-Country-and-Other-Stories-by-William-H-Gass.pdf
    • http://muicuiu.dumb1.com/5a06a05a08a04/The-Human-Comedy-by-William-Saroyan.pdf
    • http://muicuiu.dumb1.com/2a02a02a06a01/Phlogs-Journey-to-the-Heart-of-the-Human-Predicament-by-George-Stranahan.pdf
    • http://muicuiu.dumb1.com/4a01a07a04a00a00/Standing-In-Two-Circles-The-Collected-Works-Of-Boyd-Rice-by-Boyd-Rice.pdf
    • http://muicuiu.dumb1.com/9a02a07a04a04a08/Personnel-Management-and-Human-Resources-by-William-B-Werther-Jr-.pdf
    • http://muicuiu.dumb1.com/1a01a02a05a02a00a00/Steding-s-and-Viragh-s-Scanning-Electron-Microscopy-Atlas-of-the-Developing-Human-Heart-by-R-J-Oostra.pdf
    • http://muicuiu.dumb1.com/8a00a06a02a04a05/Heart-and-Humor-The-Picture-Book-Art-of-William-Steig-by-William-Steig.pdf