Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9730cd93e3eb4fe…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 03:15:49 +01:00 Authoring application: mPDF 5.7
MD5: d591e06bef0856fd5247e20070b41e59 SHA-1: f129d05689386a06de07adefd3cb1f809293b3bf SHA-256: d9730cd93e3eb4fe1895fcb4932b1ea928df36e9f11db378cb76b8da48c2e266
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and link farm heuristic suggest a malicious intent to redirect users to potentially harmful content hosted on the 'muicuiu.dumb1.com' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a05a00a09a00a05/Me-Too-Woody-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/6a04a02a06a03a01/Toy-Story-Woody-s-Aqua-Adventures-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a00a04a04a06a06/Walt-Disney-s-Worlds-of-Nature-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/5a00a03a01a04a05/Walt-Disney-s-Christmas-Parade-2-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/3a01a01a05a01a00/Cooking-with-Mickey-Around-our-World-The-Most-Requested-Recipes-from-Walt-Disney-World-and-Disneyland-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/3a04a09a06a05a03/Animation-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/2a01a05a03a00a02/The-Emperor-s-New-Clothes-Disney-s-wonderful-world-of-reading-29-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a07a00a07a01a03/Fight-to-the-Finish-Disney-Big-Hero-6-Step-into-Reading-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/5a00a03a01a03a08/Winnie-the-Pooh-s-Christmas-Stories-Disney-s-Big-Book-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a01a04a00a07a03a06/Enten-Im-All-Donaldchens-Mondfahrt-Disney-Enthologien-12-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/8a06a06a01a07a06/Disney-Frozen-Fever-Birthday-Book-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a04a00a02a08a03/Sleeping-Beauty-Disney-Classic-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a01a06a07a08a05/Beauty-and-the-Beast-Disney-Classic-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/6a07a06a03a06/Robin-Hood-Disney-s-Classic-Storybook-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/9a00a07a07a06/Aladdin-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/7a05a00a02a07/The-Aristocats-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/8a06a06a01a07a04/One-Hundred-and-One-Dalmatians-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/8a08a03a05a03/The-Jungle-Book-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a00a02a09a00a02/Beauty-and-the-Beast-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/8a05a07a00a01/The-Sword-in-the-Stone-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/2a01a05a03a00a02/The-Emperor-s-New-