Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d0d84553d82213b…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 04:56:08 +01:00 Authoring application: mPDF 5.7
MD5: f32333984e37a6bd37d0237ed6112060 SHA-1: bd469748486d539347a8118c9037437f8c0444b4 SHA-256: 9d0d84553d82213bc3811a3d1beaabbb41f567e6993e8f4a1210d02128901d2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a01a08a08a08a03/Mourning-Doves-After-the-Fire-by-Charles-D-Blanchard.pdf
    • http://muicuiu.dumb1.com/1a00a02a07a01a09/Mourning-Doves-and-other-stories-by-Tom-Upton.pdf
    • http://muicuiu.dumb1.com/3a08a09a05a06a04/Night-Stars-and-Mourning-Doves-by-Margo-Hoornstra.pdf
    • http://muicuiu.dumb1.com/4a02a07a08a04a05/Light-in-Mourning-Mourning-2-by-Adriane-Leigh.pdf
    • http://muicuiu.dumb1.com/2a02a06a07a02a02/Jet-Smoke-and-Dragon-Fire-The-Dragon-Fire-Trilogy-1-by-Charles-Ashton.pdf
    • http://muicuiu.dumb1.com/8a06a03a01a02/Novels-by-Chris-D-lacey-The-Fire-Eternal-Fire-Star-the-Fire-Within-Icefire-the-Last-Dragon-Chronicles-Fire-World-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/1a05a08a04a06a07/What-Matters-Most-is-How-Well-You-Walk-Through-the-Fire-by-Charles-Bukowski.pdf
    • http://muicuiu.dumb1.com/4a03a05a03a07a03/Path-of-Fire-The-Patterns-of-Chaos-2-by-Charles-Ingrid.pdf
    • http://muicuiu.dumb1.com/1a03a05a00a05a02/Wings-of-Fire-Inspector-Ian-Rutledge-2-by-Charles-Todd.pdf
    • http://muicuiu.dumb1.com/4a03a05a02a01a04/Return-Fire-Sand-Wars-5-by-Charles-Ingrid.pdf
    • http://muicuiu.dumb1.com/1a01a06a08a02a09a01/The-fire-in-the-rose-In-memoriam-a-ballad-of-JFK-and-other-poems-by-Alois-Charles-Taschler.pdf
    • http://muicuiu.dumb1.com/4a03a05a00a01a02/The-Sand-Wars-Volume-Two-Alien-Salute-Return-Fire-Challenge-Met-by-Charles-Ingrid.pdf
    • http://muicuiu.dumb1.com/2a09a00a09a06a09/When-Doves-Fly-by-Lauren-Gregory.pdf
    • http://muicuiu.dumb1.com/7a08a05a01a00a04/The-Plague-of-Doves-by-Louise-Erdrich.pdf
    • http://muicuiu.dumb1.com/3a08a01a04a07a01/Two-Tutor-Doves-by-Patricia-Kiyono.pdf
    • http://muicuiu.dumb1.com/5a03a06a09a06/The-Time-of-the-Doves-by-Merc-Rodoreda.pdf
    • http://muicuiu.dumb1.com/3a07a08a09a07a09/When-the-Doves-Disappeared-by-Sofi-Oksanen.pdf
    • http://muicuiu.dumb1.com/4a00a05a00a02a00/Two-Deadly-Doves-by-Donna-Andrews.pdf
    • http://muicuiu.dumb1.com/4a00a02a03a08a06/The-Plague-of-Doves-by-Louise-Erdrich.pdf
    • http://muicuiu.dumb1.com/6a02a08a01a00a08/Doves-for-Sale-Sparrows-2-by-Lila-Felix.pdf
    • http://muicuiu.dumb1.com/8a06a03a01a02/Novels-by-Chris-D-lacey-The-Fire-Eternal-Fire-Star-the-Fire-Within-Icefire-the-Last-Dragon-Chronicl