Malicious PDF — malware analysis report

Static analysis result for SHA-256 a53053b41a4b87d3…

MALICIOUS

PDF

22.2 KB Created: 2019-05-03 06:06:41 +01:00 Authoring application: mPDF 5.7
MD5: 89462ae652714998b03fe41c01b34e21 SHA-1: 31cd2307f70523dcd1c4b9d88a830b2c47c59544 SHA-256: a53053b41a4b87d34c8a7e2251d7fcce0e6d67e7eece1da8f2c61b157b3ec19e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a redirection mechanism designed to lead users to potentially malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a01a03a05a03a08/The-River-Sprite-Harlequin-Historical-No-218-by-Kate-Kingsley.pdf
    • http://muicuiu.dumb1.com/3a07a03a00a05a02/Moonlight-and-Mistletoe-Harlequin-Historical-830-by-Louise-Allen.pdf
    • http://muicuiu.dumb1.com/7a03a07a08a09a09/Harlequin-Love-Inspired-Historical-August-2016-Box-Set-An-Anthology-by-Louise-M-Gouge.pdf
    • http://muicuiu.dumb1.com/6a00a08a06a03a07/Rivers-of-Norfolk-River-Yare-River-Bure-River-Waveney-River-Nene-River-Ant-River-Thurne-North-Walsham-amp-Dilham-Canal-River-Wensum-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/7a03a01a06a02a02/No-Objections-Harlequin-Romance-3281-by-Kate-Denton.pdf
    • http://muicuiu.dumb1.com/8a07a06a09a07a06/International-Rivers-of-Asia-Ganges-Euphrates-Yalu-River-Jordan-River-Tigris-Amu-Darya-Irtysh-River-Amur-River-Hari-River-Afghanistan-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/9a05a06a06a09a00/Historical-Truth-Historical-Criticism-and-Ideology-Chinese-Historiography-and-Historical-Culture-from-a-New-Comparative-Perspective-by-Helwig-Schmidt-Glintzer.pdf
    • http://muicuiu.dumb1.com/4a00a00a06a06a09/Mistletoe-Kisses-A-Soldier-s-Tale-A-Winter-Night-s-Tale-A-Twelfth-Night-Tale-Harlequin-Historical-Series-by-Elizabeth-Rolls.pdf
    • http://muicuiu.dumb1.com/2a03a09a08a00/Ethics-in-the-Gutter-Empathy-and-Historical-Fiction-in-Comics-by-Kate-Polak.pdf
    • http://muicuiu.dumb1.com/2a05a06a02a05a01/Kingsley-amp-I-Together-Kingsley-amp-I-2-by-Gary-Martine.pdf
    • http://muicuiu.dumb1.com/1a07a03a04a09a03/The-Secret-River-by-Kate-Grenville.pdf
    • http://muicuiu.dumb1.com/7a04a05a02a07/The-Secret-River-by-Kate-Grenville.pdf
    • http://muicuiu.dumb1.com/2a07a02a07a02a09/Searching-For-The-Secret-River-by-Kate-Grenville.pdf
    • http://muicuiu.dumb1.com/7a01a03a06a00a05/Emily-Mike-Spritely-Sprite-and-the-rainbow-The-colourful-adventures-of-Emily-Mike-and-Spritely-Sprite-Book-1-by-Peter-Goldsworthy.pdf
    • http://muicuiu.dumb1.com/7a04a06a02a04a02/The-Letters-of-Kingsley-Amis-by-Kingsley-Amis.pdf
    • http://muicuiu.dumb1.com/6a00a03a05a04a08/Fiction-River-Justice-Fiction-River-An-Original-Anthology-Magazine-Book-27-by-Fiction-River.pdf
    • http://muicuiu.dumb1.com/7a01a03a05a05a00/The-Sprite-And-I-by-Rob-Shelsky.pdf
    • http://muicuiu.dumb1.com/7a01a03a05a03a06/The-Sea-Sprite-by-Jane-McIlvaine.pdf
    • http://muicuiu.dumb1.com/7a01a03a05a03a00/Sprite-Night-by-Deborah-Jay.pdf
    • http://muicuiu.dumb1.com/7a01a03a05a03a05/The-Sprite-by-David-Shaw.pdf
    • http://muicuiu.dumb1.com/7a03a01a06a02a02/No-Objections-Harlequin-Roma