Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fcdfa2727f1db55…

MALICIOUS

PDF

21.5 KB Created: 2019-04-30 03:37:56 +01:00 Authoring application: mPDF 5.7
MD5: cf4ccd3ebab7ccd323479904450ed44d SHA-1: 5a9d013e7cf0560fe01d14a41ef9fe4a57b9f21d SHA-256: 9fcdfa2727f1db55cfb2c96acb3bd4250fa9a3f0d3ee24c59e351ac2dafaf1cc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. The document body, though heavily obfuscated, contains URLs pointing to the suspicious domain 'muicuiu.dumb1.com'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.d
    • http://muicuiu.dumb1.com/2a02a04a07a06a07/Notorious-Woman-The-Celebrated-Case-of-Myra-Clark-Gaines-by-Elizabeth-Urban-Alexander.pdf
    • http://muicuiu.dumb1.com/5a02a01a07a08a07/Getting-Away-with-Murder-on-the-Texas-Frontier-Notorious-Killings-and-Celebrated-Trials-by-Bill-Neal.pdf
    • http://muicuiu.dumb1.com/9a09a04a00a07a02/Defending-Donald-Harvey-The-Case-of-America-s-Most-Notorious-Angel-of-Death-Serial-Killer-by-William-Whalen.pdf
    • http://muicuiu.dumb1.com/4a00a06a04a01a02/Notorious-Pleasures-Maiden-Lane-2-by-Elizabeth-Hoyt.pdf
    • http://muicuiu.dumb1.com/2a08a01a04a09a01/Notorious-Pleasures-Maiden-Lane-2-by-Elizabeth-Hoyt.pdf
    • http://muicuiu.dumb1.com/4a07a09a04a08a01/Myra-Stolen-Innocence-by-Myra-Zhivanevskaya.pdf
    • http://muicuiu.dumb1.com/8a09a04a06a00a09/Wurst-Case-Scenario-Courtney-Von-Dragen-Smith-2-by-Catherine-Clark.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a01a02/The-Case-of-the-Missing-Boyfriend-by-Nick-Alexander.pdf
    • http://muicuiu.dumb1.com/1a00a09a03a09a08a03/The-Case-of-the-Missing-Boyfriend-by-Nick-Alexander.pdf
    • http://muicuiu.dumb1.com/7a08a02a02a06/Scandalous-Women-The-Lives-and-Loves-of-History-s-Most-Notorious-Women-by-Elizabeth-Kerri-Mahon.pdf
    • http://muicuiu.dumb1.com/7a07a01a02a00a07/The-Sphinx-in-the-City-Urban-Life-the-Control-of-Disorder-and-Women-by-Elizabeth-Wilson.pdf
    • http://muicuiu.dumb1.com/6a07a03a01a05a00/Becoming-a-Woman-of-Worth-Creating-a-More-Confident-You-by-Kristen-Clark.pdf
    • http://muicuiu.dumb1.com/3a00a00a08a03a04/A-Young-Woman-s-Call-to-Prayer-Talking-with-God-About-Your-Life-George-Elizabeth-by-Elizabeth-George.pdf
    • http://muicuiu.dumb1.com/4a02a09a03a00a03/Mrs-Oscar-Wilde-A-Woman-of-Some-Importance-by-Anne-Clark-Amor.pdf
    • http://muicuiu.dumb1.com/1a00a09a02a09a02/An-Old-Woman-s-Last-Prophecy-The-Forsaken-Elvish-Scrolls-Trilogy-1-by-J-A-Clark.pdf
    • http://muicuiu.dumb1.com/8a03a05a06a09a05/Who-s-Notorious-Now-Notorious-3-by-Kiki-Swinson.pdf
    • http://muicuiu.dumb1.com/7a05a06a01a09/The-Woman-Who-Swallowed-a-Toothbrush-And-Other-Weird-Medical-Case-Histories-by-Rob-Myers.pdf
    • http://muicuiu.dumb1.com/7a08a07a03a04a03/Let-Me-Be-Clear-Barack-Obama-s-War-on-Millennials-and-One-Woman-s-Case-for-Hope-by-Katie-Kieffer.pdf
    • http://muicuiu.dumb1.com/1a04a09a01a03a09/The-Mummy-Case-Amelia-Peabody-3-by-Elizabeth-Peters.pdf
    • http://muicuiu.dumb1.com/9a01a09a03a00/The-Black-Interior-Essays-by-Elizabeth-Alexander.pdf