Malicious PDF — malware analysis report

Static analysis result for SHA-256 aee359831bb5b0c8…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 04:59:21 +01:00 Authoring application: mPDF 5.7
MD5: 6cbccf2df4f29865d0c1598fba3ea822 SHA-1: fe5effc3e59925c3b02ca8de01498fa94623c6df SHA-256: aee359831bb5b0c8e1065db55e2d5950aa51f10a6157dab81c6f9a7f88de7f21
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded URLs, such as http://muicuiu.dumb1.com/9a07a06a08a08a06/Glockenspiele-Geile-Kerle-unter-sich-by-Thorsten-Lubert.pdf, are likely part of a link farm designed to direct users to malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a07a06a08a08a06/Glockenspiele-Geile-Kerle-unter-sich-by-Thorsten-Lubert.pdf
    • http://muicuiu.dumb1.com/1a00a09a02a09a07a09/Thorsten-Brinkmann-Life-Is-Funny-My-Deer-by-Thorsten-Brinkmann.pdf
    • http://muicuiu.dumb1.com/7a03a02a07a06a07/Was-sich-neckt-das-k-sst-sich-by-Susan-Mallery.pdf
    • http://muicuiu.dumb1.com/1a00a02a05a08a07a08/Wessobrunnische-Marianische-Fama-in-Sich-Haltend-Die-Weitere-Merckw-Rdigiste-Begebenheiten-Welche-Sich-In--Und-Um-Das-Jahr-1745-Ereignet-Bey-Der-Hoch--Und-Weltber-Hmten-Haupt-Bruderschafft-Der-Unbefleckten-Emf-Ngnu-Mariae-Der-Wunderth-Tigen-by-Veremund-Eisvogel.pdf
    • http://muicuiu.dumb1.com/9a07a06a07a00a04/Kerle-der-Nacht-Tom-by-Mo-von-Winter.pdf
    • http://muicuiu.dumb1.com/9a07a06a08a07a06/Im-Schatten-meiner-selbst-by-Linda-Kerle.pdf
    • http://muicuiu.dumb1.com/9a07a07a00a02a00/American-Jails-Looking-to-the-Future-by-Kenneth-E-Kerle.pdf
    • http://muicuiu.dumb1.com/9a07a06a08a09a04/F-nf-Mal-Kerle-und-Geburtstage-by-Sissi-Kaipurgay.pdf
    • http://muicuiu.dumb1.com/9a07a06a08a08a04/Erotische-Phantasien-f-r-hei-e-Kerle-by-Roland-Klein.pdf
    • http://muicuiu.dumb1.com/9a07a06a08a09a00/Die-Hotwife-Fantasien-eifersuchtsloser-Kerle-by-Geoffrey-van-der-Beulen.pdf
    • http://muicuiu.dumb1.com/1a01a05a09a02a08a01/Die-Pubert-t-ist-ein-Arschloch-by-Thorsten-Peter.pdf
    • http://muicuiu.dumb1.com/1a01a03a06a03a09a02/M-rderische-Technologie-by-Thorsten-McKay.pdf
    • http://muicuiu.dumb1.com/6a04a00a09a00a03/Der-Nomade-im-Speck-by-Thorsten-Fiedler.pdf
    • http://muicuiu.dumb1.com/8a07a05a03a08a00/Das-Rathaus-in-L-neburg-by-Thorsten-Albrecht.pdf
    • http://muicuiu.dumb1.com/1a01a08a02a07a01a00/Wasserzeichen-die-Warheit-unter-der-Oberfl-che-Die-Warheit-unter-der-Oberfl-che-by-Sari-Sikstrom.pdf
    • http://muicuiu.dumb1.com/1a00a06a08a05a08a02/Planetenwelten-In-den-Tiefen-des-Sonnensystems-by-Thorsten-Dambeck.pdf
    • http://muicuiu.dumb1.com/9a07a07a01a02a01/Flammen-am-Horizont-BEHIND-THE-FLAMES---Hei-e-Kerle-in-Uniform-2-by-Anie-Salvatore.pdf
    • http://muicuiu.dumb1.com/9a07a06a07a00a08/Uners-ttlich---Einer-ist-nicht-genug-3-Macho-Kerle-by-Ruth-Broucq.pdf
    • http://muicuiu.dumb1.com/1a01a06a03a09a00a09/Entstehen-Niedergang-und-Organisation-der-Hanse-by-Thorsten-Lemmer.pdf
    • http://muicuiu.dumb1.com/1a01a02a02a08a03a04/Hans-Aichinger-Truth-or-Duty-by-Thorsten-Reiter.pdf