Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2871ebf1108cc4d…

MALICIOUS

PDF

19.2 KB Created: 2019-05-03 06:08:34 +01:00 Authoring application: mPDF 5.7
MD5: 798df857b023657beafb05bbe765bbde SHA-1: b0ecb4efb5728cc72f100de6a85dd884c2e7807c SHA-256: a2871ebf1108cc4d5682ef473bfe99225fe73ffcb96de1682b99725a6ed6267c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a09a08a07a01a04/Tiny-Dancer-Divine-Creek-Ranch-13-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/3a06a08a02a08a03/Sparks-Fly-a-Divine-Creek-July-4th-Family-Reunion-Divine-Creek-Ranch-11-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/3a06a08a02a08a02/Tangled-in-Divine-Divine-Creek-Ranch-14-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/3a03a02a02a05a03/Margot-s-Hunger-Divine-Creek-Ranch-11-5-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/4a09a07a03a05a01/Absentminded-Angel-Divine-Creek-Ranch-20-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/2a09a07a02a07a09/Her-Gentle-Giant-Part-1-No-Regrets-Divine-Creek-Ranch-2-by-Heather-Rainier.pdf
    • http://muicuiu.dumb1.com/9a05a03a07/The-Pines-of-Winder-Ranch-A-Cold-Creek-Homecoming-A-Cold-Creek-Reunion-by-RaeAnne-Thayne.pdf
    • http://muicuiu.dumb1.com/2a04a01a03a00a07/Trouble-Brewing-in-Thunder-Creek-Thunder-Creek-Ranch-3-by-Lorraine-Nelson.pdf
    • http://muicuiu.dumb1.com/1a07a09a01a06a03/A-Cowgirl-s-Pride-Thunder-Creek-Ranch-4-by-Lorraine-Nelson.pdf
    • http://muicuiu.dumb1.com/7a05a09a02a03a00/Chester-Gump-at-Silver-Creek-Ranch-by-Sidney-Smith.pdf
    • http://muicuiu.dumb1.com/3a09a07a00a07a08/Gage-The-Lawmen-of-Silver-Creek-Ranch-5-by-Delores-Fossen.pdf
    • http://muicuiu.dumb1.com/2a02a00a01a02a02/Camerons-Quest-Thunder-Creek-Ranch-5-by-Lorraine-Nelson.pdf
    • http://muicuiu.dumb1.com/2a01a09a08a03a09/Crazy-Thing-Called-Love-Crooked-Creek-Ranch-3-by-Molly-O-39-Keefe.pdf
    • http://muicuiu.dumb1.com/3a04a08a02a09a06/True-Love-at-Silver-Creek-Ranch-Valentine-Valley-2-by-Emma-Cane.pdf
    • http://muicuiu.dumb1.com/3a06a09a09a00a00/Out-of-Circulation-Hemlock-Creek-Suspense-1-by-Heather-Day-Gilbert.pdf
    • http://muicuiu.dumb1.com/8a04a09a08a07a07/Tiny-Buddha-s-365-Tiny-Love-Challenges-by-Lori-Deschene.pdf
    • http://muicuiu.dumb1.com/4a08a08a03a09a08/Tiny-Houses-Built-with-Recycled-Materials-Inspiration-for-Constructing-Tiny-Homes-Using-Salvaged-and-Reclaimed-Supplies-by-Ryan-Mitchell.pdf
    • http://muicuiu.dumb1.com/4a09a03a09a00a07/Holiday-in-Stone-Creek-A-Stone-Creek-Christmas-At-Home-in-Stone-Creek-Stone-Creek-4-amp-6-by-Linda-Lael-Miller.pdf
    • http://muicuiu.dumb1.com/9a02a09a01a09a06/When-Tiny-Was-Tiny-by-Cari-Meister.pdf
    • http://muicuiu.dumb1.com/2a05a03a08a07a03/Teeny-Tiny-Tina-the-Teeny-Tiny-Tooth-Fairy-by-Rosemary-R-Evans.pdf