Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a45177ce4a5a92a…

MALICIOUS

PDF

16.2 KB Created: 2019-05-06 16:59:31 +01:00 Authoring application: mPDF 5.7
MD5: 594ce2bdfdfb49dcbb8c84464f33075f SHA-1: 9783a53767815a5913d72d3127d8619aef00d840 SHA-256: 9a45177ce4a5a92a11e03fd4c1070606ea68345f83f397092e8a93bb8e9a120f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'muicuiu.dumb1.com'. This pattern is indicative of a link farm designed to direct users to potentially malicious content or to manipulate search engine rankings. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.co
    • http://muicuiu.dumb1.com/8a07a02a00a01a07/The-Mythical-Creatures-Bible-Everything-You-Ever-Wanted-To-Know-About-Mythical-Creatures-by-Brenda-Rosen.pdf
    • http://muicuiu.dumb1.com/2a00a07a03a01a01/Mythical-Stone-Soldiers-1-by-C-E-Martin.pdf
    • http://muicuiu.dumb1.com/3a05a04a01a05a06/Heart-of-Stone-Mythical-1-by-C-E-Martin.pdf
    • http://muicuiu.dumb1.com/1a01a00a09a03a05a08/Mythical-Detective-Loki-Vol-05-by-Sakura-Kinoshita.pdf
    • http://muicuiu.dumb1.com/1a01a00a09a03a04a09/Mythical-Detective-Loki-Vol-02-by-Sakura-Kinoshita.pdf
    • http://muicuiu.dumb1.com/2a07a01a02a00a00/Gabby-a-Mythical-Journey-by-Alan-Stephenson.pdf
    • http://muicuiu.dumb1.com/3a07a04a08a04a04/It-Doesn-t-Exist-Mythical-Stories-by-Corinne-Mucha.pdf
    • http://muicuiu.dumb1.com/9a00a02a03a01/The-Mythical-Man-Month-Essays-on-Software-Engineering-by-Frederick-P-Brooks-Jr-.pdf
    • http://muicuiu.dumb1.com/7a07a00a02a04a00/Mythical-Trickster-Figures-Contours-Contexts-and-Criticisms-by-William-J-Hynes.pdf
    • http://muicuiu.dumb1.com/2a09a08a01a09a02/In-Search-of-Lost-Books-The-Forgotten-Stories-of-Eight-Mythical-Volumes-by-Giorgio-van-Straten.pdf
    • http://muicuiu.dumb1.com/4a07a09a04a00a00/Bug-Fun-Creatures-of-the-World-by-N-V-Smith.pdf
    • http://muicuiu.dumb1.com/4a00a04a01a09a04/Winged-Creatures-A-Novel-by-Roy-Freirich.pdf
    • http://muicuiu.dumb1.com/2a06a08a02a02a00/All-the-Devil-s-Creatures-by-J-D-Barnett.pdf
    • http://muicuiu.dumb1.com/8a02a01a02a07a01/Sea-Creatures-by-Robert-Coupe.pdf
    • http://muicuiu.dumb1.com/3a05a03a02a02a02/Hideous-Creatures-by-S-E-Lister.pdf
    • http://muicuiu.dumb1.com/9a09a08a06a06a06/Creatures-That-Once-Were-Men-by-Maxim-Gorky.pdf
    • http://muicuiu.dumb1.com/9a03a04a04/Creatures-of-Want-and-Ruin-by-Molly-Tanzer.pdf
    • http://muicuiu.dumb1.com/3a08a05a03a05a01/Irregular-Creatures-by-Chuck-Wendig.pdf
    • http://muicuiu.dumb1.com/1a00a08a01a06a02/The-Last-Glass-The-Creatures-of-Grimmsburg-1-by-T-M-Lazar.pdf
    • http://muicuiu.dumb1.com/2a06a03a09a04a05/Remarkable-Creatures-by-Tracy-Chevalier.pdf