Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef3c4e19d22eb310…

MALICIOUS

PDF

21.9 KB Created: 2019-04-30 04:11:04 +01:00 Authoring application: mPDF 5.7
MD5: 7120a98c03393573dc969c159b9aff53 SHA-1: fbbd374c8165dae03ea9a3c79f15744205ac4f29 SHA-256: ef3c4e19d22eb3100f84b1a70e869cb93b277bb10678d8b7c2d50c8f77e9a75e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates these links are likely part of a scheme to distribute content or drive traffic. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect the user to potentially harmful content hosted on the 'muicuiu.dumb1.com' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a03a06a09a05/Born-to-Spy-by-Jayde-Scott.pdf
    • http://muicuiu.dumb1.com/3a06a07a01a07a07/A-Job-From-Hell-Ancient-Legends-1-by-Jayde-Scott.pdf
    • http://muicuiu.dumb1.com/3a07a07a04a09/Doomed-Ancient-Legends-2-by-Jayde-Scott.pdf
    • http://muicuiu.dumb1.com/4a05a04a00a09a05/Ancient-Legends-The-Complete-Collection-Ancient-Legends-1-6-by-Jayde-Scott.pdf
    • http://muicuiu.dumb1.com/1a09a05a04a04a06/Dead-Jed-3-Return-of-the-Jed-by-Scott-Craven.pdf
    • http://muicuiu.dumb1.com/1a08a05a06a06a02/Waking-the-Dead-by-Scott-Spencer.pdf
    • http://muicuiu.dumb1.com/7a04a08a02a03a00/Dead-Before-Docking-by-Scott-Corbett.pdf
    • http://muicuiu.dumb1.com/1a01a01a01a07a09/Living-Dead-Girl-by-Elizabeth-Scott.pdf
    • http://muicuiu.dumb1.com/2a09a07a09a07a03/Wanted-Dead-or-Undead-Zombie-West-1-by-Angela-Scott.pdf
    • http://muicuiu.dumb1.com/4a04a00a00a00a07/The-Grey-Tier-A-Dead-Celeb-Mystery-by-Michele-Scott.pdf
    • http://muicuiu.dumb1.com/4a02a09a05a08a03/True-Blood-Omnibus-2-Dead-to-the-World-Dead-as-a-Doornail-Definitely-Dead-Sookie-Stackhouse-4-6-by-Charlaine-Harris.pdf
    • http://muicuiu.dumb1.com/1a01a08a09a09a00a08/Flappers-and-Philosophers-1920-by-Francis-Scott-Fitzgerald-Francis-Scott-Key-Fitzgerald-September-24-1896---December-21-1940-Known-Professionally-as-F-Scott-Fitzgerald-Was-an-American-Novelist-and-Short-Story-Writer-Whose-Works-Illustrate-by-F-Scott-Fitzgerald.pdf
    • http://muicuiu.dumb1.com/9a08a05a04a02a05/Ivanhoe-by-Sir-Walter-Scott-Illustrated-Delphi-Parts-Edition-Sir-Walter-Scott-by-Walter-Scott.pdf
    • http://muicuiu.dumb1.com/4a04a01a01a07a07/Living-with-the-Dead-Twenty-Years-on-the-Bus-with-Garcia-and-the-Grateful-Dead-by-Rock-Scully.pdf
    • http://muicuiu.dumb1.com/4a00a01a02a03a09/The-Hungry-Dead-Zombies-Vampires-Ghosts-and-Other-Dead-Things-That-Want-to-Eat-You-by-Lester-Smith.pdf
    • http://muicuiu.dumb1.com/2a03a00a06a06a05/Dead-by-Midnight-Dead-by-Trilogy-1-Griffin-Powell-11-by-Beverly-Barton.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a03a09/United-States-of-the-Dead-White-Flag-of-the-Dead-4-by-Joseph-Talluto.pdf
    • http://muicuiu.dumb1.com/1a00a06a09a03a02a04/Conversations-With-The-Dead-The-Grateful-Dead-Interview-Book-by-David-Gans.pdf
    • http://muicuiu.dumb1.com/8a08a02a05a08/Dear-Scott-Dearest-Zelda-The-Love-Letters-of-F-Scott-and-Zelda-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a03a00/Dead-Surge-White-Flag-of-the-Dead-5-by-Joseph-Talluto.pdf
    • http://muicuiu.dumb1.com/4a02a09a05a08a03/True-Blood-Omnibus-2-Dead-to-the-World-Dead-as-a-Doornail-Definitely-Dead-Sookie-Stackhouse-4-6-by-Charlaine-Harris.pd