Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3de9b540e2ce3aa…

MALICIOUS

PDF

18.4 KB Created: 2019-05-02 00:50:30 +01:00 Authoring application: mPDF 5.7
MD5: 7e463012b235347124d1ac3c86e67e61 SHA-1: 12d93ddcc739f563398e54f8530dc974008443f7 SHA-256: b3de9b540e2ce3aaf69ead516fe5523120f76540ba6acd01f1e51ff1ee2888f7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded external links, identified as a link farm. The ML classifier strongly indicated maliciousness. No scripts were extracted, but the structure suggests a lure to external content, likely for further malicious activity. The primary attack pattern involves directing users to a multitude of PDF documents hosted on the domain muicuiu.dumb1.com.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a01a05a04a05/Brothers-in-Hope-The-Story-of-the-Lost-Boys-of-Sudan-by-Mary-Williams.pdf
    • http://muicuiu.dumb1.com/4a06a08a07a05a02/The-Lost-Daughter-A-Memoir-by-Mary-Williams.pdf
    • http://muicuiu.dumb1.com/2a04a00a04a09a05/The-Black-Hope-Horror-The-True-Story-of-a-Haunting-by-Ben-Williams.pdf
    • http://muicuiu.dumb1.com/1a07a06a09a03/American-Boys-The-True-Story-of-the-Lost-74-of-the-Vietnam-War-by-Louise-Esola.pdf
    • http://muicuiu.dumb1.com/1a01a05a08a04a08a04/Hope-Pain-and-Patience-The-Lives-of-Women-in-South-Sudan-by-Friederike-Bubenzer.pdf
    • http://muicuiu.dumb1.com/1a01a05a08a04a09a04/Hope-Pain-and-Patience---The-Lives-of-Women-in-South-Sudan-by-Friederike-Bubenzer.pdf
    • http://muicuiu.dumb1.com/2a08a05a02a08a05/Loving-a-Lost-Lord-Lost-Lords-1-by-Mary-Jo-Putney.pdf
    • http://muicuiu.dumb1.com/8a01a02a09a01/Never-Goodbye-Albany-Boys-1-by-Kerri-Williams.pdf
    • http://muicuiu.dumb1.com/1a04a04a09a06a05/Bad-Boys-Do-Donovan-Brothers-Brewery-2-by-Victoria-Dahl.pdf
    • http://muicuiu.dumb1.com/3a00a09a06a01a07/Only-an-Idiot-Gets-Lost-in-Chicago-A-Story-of-Lost-Dreams-by-Mike-Reuther.pdf
    • http://muicuiu.dumb1.com/7a02a06a07a02/Brian-Wilson-amp-the-Beach-Boys-How-Deep-Is-the-Ocean-by-Paul-Williams.pdf
    • http://muicuiu.dumb1.com/9a06a07a06a04a08/The-Castell-Brothers-Trilogy-Boxed-Set-by-Izzy-Williams.pdf
    • http://muicuiu.dumb1.com/9a00a08a03a09a09/Redemption-A-Novel-about-Hope-and-Human-Trafficking-Boys-For-Sale-2-by-Marc-Finks.pdf
    • http://muicuiu.dumb1.com/9a02a04a02a06a02/Sleigh-of-Hope-Grayson-Brothers-5-by-Wendy-Lindstrom.pdf
    • http://muicuiu.dumb1.com/1a09a00a02a01a05/Devil-You-Know-Lost-Boys-1-by-L-A-Fiore.pdf
    • http://muicuiu.dumb1.com/2a09a01a05a00a03/An-Alcoholic-Husband---a-Story-of-Love-and-Hope-The-extraordinary-true-story-of-one-woman-s-journey-married-to-a-loveable-rogue-by-Carol-Mills.pdf
    • http://muicuiu.dumb1.com/2a02a02a03a00a04/Lost-Boys-by-Orson-Scott-Card.pdf
    • http://muicuiu.dumb1.com/4a04a02a01a03a09/Lost-Boys-by-Orson-Scott-Card.pdf
    • http://muicuiu.dumb1.com/1a04a05a03a00a04/Near-and-Far-Lost-amp-Found-2-by-Nicole-Williams.pdf
    • http://muicuiu.dumb1.com/4a02a02a03a00a08/Green-Vanilla-Tea-One-Family-s-Extraordinary-Journey-of-Love-Hope-and-Remembering-by-Marie-Williams.pdf
    • http://muicuiu.dumb1.com/7a02a06a07a02/Brian-Wilson-amp-th