Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1e78fd222f375ac…

MALICIOUS

PDF

22.9 KB Created: 2019-04-29 23:06:06 +01:00 Authoring application: mPDF 5.7
MD5: c6ce0c720406c4054d68cc6a2afdf23b SHA-1: bbcc9c6172f28b5d2fa6dc1fba61cbb400b25b28 SHA-256: d1e78fd222f375accfc57a0545bf2bb7927e6142a171bd21012008a1b93d85f8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9726

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a09a09a07a05a07/Bike-Boys-Drag-Queens-and-Superstars-Avant-Garde-Mass-Culture-and-Gay-Identities-in-the-1960s-Underground-Cinema-by-Juan-Antonio-Suarez.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a02a00a01/The-Downtown-Pop-Underground-New-York-City-and-the-literary-punks-renegade-artists-DIY-filmmakers-mad-playwrights-and-rock-n-roll-glitter-queens-who-revolutionized-culture-by-Kembrew-McLeod.pdf
    • http://muicuiu.dumb1.com/9a01a04a06a07a00/Jim-Jarmusch-by-Juan-A-Suarez.pdf
    • http://muicuiu.dumb1.com/3a03a05a07a04a01/Avant-Garde-Society-Vol-1-by-Emerson-Barrett.pdf
    • http://muicuiu.dumb1.com/1a05a06a05a06a05/Splintered-Avant-Garde-1-by-Hope-Christine.pdf
    • http://muicuiu.dumb1.com/5a09a08a01a07a04/Crescendo-Boston-Avant-Garde-2-by-Kaitlin-Maitland.pdf
    • http://muicuiu.dumb1.com/5a06a09a06a02a02/Apollinaire-and-the-International-Avant-Garde-by-Willard-Bohn.pdf
    • http://muicuiu.dumb1.com/8a07a02a00a02a08/Pocketbook-of-Drag-Queens-by-Ellen-Wallenstein.pdf
    • http://muicuiu.dumb1.com/9a06a07a00a05a00/Theodor-Fahrner-Jewellery-Between-Avant-Garde-and-Tradition-by-B-Leonhard.pdf
    • http://muicuiu.dumb1.com/5a09a08a01a09a06/The-Politics-of-Time-Modernity-and-Avant-Garde-by-Peter-Osborne.pdf
    • http://muicuiu.dumb1.com/3a09a09a03a01a03/Guy-to-Goddess-An-Intimate-Look-at-Drag-Queens-by-Rosamond-Norbury.pdf
    • http://muicuiu.dumb1.com/5a09a01a06a04a02/The-Mattioli-Collection-Masterpieces-of-the-Italian-Avant-garde-by-Flavio-Fergonzi.pdf
    • http://muicuiu.dumb1.com/5a09a08a01a08a01/The-Bauhaus-1919-1933-Reform-and-Avant-Garde-by-Magdalena-Droste.pdf
    • http://muicuiu.dumb1.com/8a08a09a06a01a03/Source-Music-of-the-Avant-garde-1966-1973-by-Larry-Austin.pdf
    • http://muicuiu.dumb1.com/1a08a03a03a09a04/Women-Destruction-and-the-Avant-Garde-A-Paradigm-for-Animal-Liberation-by-Kim-Socha.pdf
    • http://muicuiu.dumb1.com/1a01a05a07a09a08a03/Modern-French-Theatre-The-Avant-Garde-Dada-and-Surrealism-by-Michael-Benedikt.pdf
    • http://muicuiu.dumb1.com/6a06a01a00a03a09/Theater-of-the-Avant-Garde-1890-1950-A-Critical-Anthology-by-Bert-Cardullo.pdf
    • http://muicuiu.dumb1.com/1a01a06a05a02a00a03/MAVO-Japanese-Artists-and-the-Avant-Garde-1905-1931-by-Gennifer-Weisenfeld.pdf
    • http://muicuiu.dumb1.com/5a01a07a07a06a01/The-Aesthetics-of-Anarchy-Art-and-Ideology-in-the-Early-Russian-Avant-Garde-by-Nina-Gurianova.pdf
    • http://muicuiu.dumb1.com/2a08a04a01a02a01/The-Banquet-Years-The-Origins-of-the-Avant-Garde-in-France-1885-to-World-War-I-by-Roger-Shattuck.pdf