Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f37ce22ed1af6f9…

MALICIOUS

PDF

21.9 KB Created: 2019-05-01 05:13:37 +01:00 Authoring application: mPDF 5.7
MD5: 51174da5063d159bacf897c52aef94d2 SHA-1: a51eef77a450cbc64912cbe5412adb5a8fde82da SHA-256: 9f37ce22ed1af6f96c84a348481e808a23da45a7a86c90f833896c7546d3d562
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to external PDF documents. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs appear to be part of a link farm designed to drive traffic or potentially distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.co
    • http://muicuiu.dumb1.com/1a08a05a09a01a09/The-Life-You-Can-Save-Acting-Now-to-End-World-Poverty-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/5a07a01a04a07/One-World-The-Ethics-Of-Globalisation-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/5a03a09a01a07a01/Writings-on-an-Ethical-Life-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/1a08a03a01a02a03/The-Food-Revolution-How-Your-Diet-Can-Help-Save-Your-Life-and-Our-World-by-John-Robbins.pdf
    • http://muicuiu.dumb1.com/5a08a08a02a03a02/The-Genome-War-How-Craig-Venter-Tried-to-Capture-the-Code-of-Life-and-Save-the-World-by-James-Shreeve.pdf
    • http://muicuiu.dumb1.com/4a02a08a08a02a02/Urgent-Message-From-Mother-Gather-the-Women-and-Save-the-World-Gather-the-Women-Save-the-World-by-Jean-Shinoda-Bolen.pdf
    • http://muicuiu.dumb1.com/1a07a09a09a02/The-Answer-to-How-Is-Yes-Acting-on-What-Matters-by-Peter-Block.pdf
    • http://muicuiu.dumb1.com/1a01a00a01a06a07a00/Life-Child-The-End-of-Poverty-The-Case-for-Licensing-All-Parents-Life-Force-series-by-Randall-Craig-Fasnacht.pdf
    • http://muicuiu.dumb1.com/1a00a04a04a00a04a00/The-New-Plagues-Pandemics-and-Poverty-in-a-Globalized-World-by-Stefan-Kaufmann.pdf
    • http://muicuiu.dumb1.com/9a05a04a04a05a05/Playing-to-the-Gods-Sarah-Bernhardt-Eleonora-Duse-and-the-Rivalry-that-Changed-Acting-Forever-by-Peter-Rader.pdf
    • http://muicuiu.dumb1.com/5a03a09a01a07a07/How-Are-We-to-Live-Ethics-in-an-Age-of-Self-Interest-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a07a02/The-Way-We-Eat-Why-Our-Food-Choices-Matter-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/3a09a04a04a05a03/Marx-A-Very-Short-Introduction-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/3a03a02a07a01a04/The-Hidden-Life-of-Trees-What-They-Feel-How-They-Communicate-Discoveries-from-a-Secret-World-by-Peter-Wohlleben.pdf
    • http://muicuiu.dumb1.com/4a05a07a04a03a04/Save-Me-by-Peter-Styles.pdf
    • http://muicuiu.dumb1.com/3a09a04a04a05a01/A-Darwinian-Left-Politics-Evolution-and-Cooperation-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/1a01a09a05a03a09a08/Dear-Lilly-From-Father-to-Daughter-The-Truth-about-Life-Love-and-the-World-We-Live-in-by-Peter-Greyson.pdf
    • http://muicuiu.dumb1.com/1a01a09a01a07a02a00/Acting-One-Acting-Two-by-Robert-Cohen.pdf
    • http://muicuiu.dumb1.com/1a00a08a09a01a03a08/Pushing-Time-Away-My-Grandfather-and-the-Tragedy-of-Jewish-Vienna-by-Peter-Singer.pdf
    • http://muicuiu.dumb1.com/2a05a03a06a04a06/Ghost-Fleet-A-Novel-of-the-Next-World-War-by-P-W-Singer.pdf