Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5a6a82c0cb86505…

MALICIOUS

PDF

22.3 KB Created: 2019-05-05 14:25:35 +01:00 Authoring application: mPDF 5.7
MD5: 7bcdbb3436d43a4564cd6f77fae30c31 SHA-1: b5d49e09b5916c37acb33a1e8adeaa2af8adc890 SHA-256: c5a6a82c0cb8650564df077374a6745313272d83565828fcce4aea8cd7f7db5c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a00a04a07a07a04/The-Impossible-State-North-Korea-Past-and-Future-by-Victor-Cha.pdf
    • http://muicuiu.dumb1.com/2a00a04a08a03a02/Nuclear-North-Korea-A-Debate-on-Engagement-Strategies-by-Victor-Cha.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a04a00a03/Liberating-the-Future-from-the-Past-Liberating-the-Past-from-the-Future-A-Short-Listed-Essay-by-Erika-Schelby.pdf
    • http://muicuiu.dumb1.com/4a09a05a02a05a02/Korea-The-Impossible-Country-by-Daniel-Tudor.pdf
    • http://muicuiu.dumb1.com/3a06a00a01a05/Pyongyang-A-Journey-in-North-Korea-by-Guy-Delisle.pdf
    • http://muicuiu.dumb1.com/4a08a06a07a01a04/Pyongyang-A-Journey-in-North-Korea-by-Guy-Delisle.pdf
    • http://muicuiu.dumb1.com/6a00a01a04a08/Without-You-There-Is-No-Us-My-Time-with-the-Sons-of-North-Korea-s-Elite-by-Suki-Kim.pdf
    • http://muicuiu.dumb1.com/2a00a04a08a02a05/Famine-in-North-Korea-Markets-Aid-and-Reform-by-Stephan-Haggard.pdf
    • http://muicuiu.dumb1.com/7a01a08a06/A-River-in-Darkness-One-Man-s-Escape-from-North-Korea-by-Masaji-Ishikawa.pdf
    • http://muicuiu.dumb1.com/2a05a08a02a07a02/Nothing-to-Envy-Ordinary-Lives-in-North-Korea-by-Barbara-Demick.pdf
    • http://muicuiu.dumb1.com/2a00a04a07a09a07/Comrades-and-Strangers-Behind-the-Closed-Doors-of-North-Korea-by-Michael-Harrold.pdf
    • http://muicuiu.dumb1.com/1a00a08a03a01a05a09/The-Koreans-America-s-Troubled-Relations-with-North-and-South-Korea-by-Michael-Breen.pdf
    • http://muicuiu.dumb1.com/2a00a04a08a02a03/Tyranny-of-the-Weak-North-Korea-and-the-World-1950-1992-by-Charles-K-Armstrong.pdf
    • http://muicuiu.dumb1.com/4a01a01a09/Every-Falling-Star-The-True-Story-of-How-I-Survived-and-Escaped-North-Korea-by-Sungju-Lee.pdf
    • http://muicuiu.dumb1.com/2a00a04a07a08a03/My-Holiday-in-North-Korea-The-Funniest-Worst-Place-on-Earth-by-Wendy-E-Simmons.pdf
    • http://muicuiu.dumb1.com/1a08a04a01a00a08/Every-Falling-Star-The-True-Story-of-How-I-Survived-and-Escaped-North-Korea-by-Sungju-Lee.pdf
    • http://muicuiu.dumb1.com/4a01a00a06a00a02/Deep-War-The-War-with-China-and-North-Korea-The-Nuclear-Precipice-Dan-Lenson-18-by-David-Poyer.pdf
    • http://muicuiu.dumb1.com/2a00a04a07a09a09/The-Hidden-People-of-North-Korea-Everyday-Life-in-the-Hermit-Kingdom-by-Ralph-Hassig.pdf
    • http://muicuiu.dumb1.com/2a05a04a06a04a05/Escape-from-Camp-14-One-Man-s-Remarkable-Odyssey-from-North-Korea-to-Freedom-In-the-West-by-Blaine-Harden.pdf
    • http://muicuiu.dumb1.com/2a00a04a07a09a02/Stars-Between-the-Sun-and-Moon-One-Woman-s-Life-in-North-Korea-and-Escape-to-Freedom-by-Lucia-Jang.pdf
    • http://muicuiu.dumb1.com/2a00a04a08a02a05/Famine-in-North-Korea-Market