Malicious PDF — malware analysis report

Static analysis result for SHA-256 f32c8367d8517c91…

MALICIOUS

PDF

16.1 KB Created: 2019-04-29 23:28:48 +01:00 Authoring application: mPDF 5.7
MD5: 0dbb5801602194428134204b85288161 SHA-1: 8c13cdada6680beb641bfb706c528371a7ebcca8 SHA-256: f32c8367d8517c9154bb436ed09f69833d2522f44ddfd3808fed54e86d3d3689
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of external links, identified as a link farm. The ML classifier also flagged this PDF as malicious. While the specific intent beyond linking is unclear due to the lack of executable scripts or a clear document body, the sheer volume of links suggests a malicious attempt to drive traffic or distribute further content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.c
    • http://muicuiu.dumb1.com/9a08a08a01a04a06/Nackt-jung-und-verheiratet-by-Models18.pdf
    • http://muicuiu.dumb1.com/9a08a07a08a09a08/-quot-Nackt-Sexbilder-Xxx-Nackt-Bilder-F-r-Sie-by-Ester-Haas.pdf
    • http://muicuiu.dumb1.com/1a00a09a02a01a05a08/Praktische-Handreichung-Fuer-Fremdsprachenlehrer-In-Zusammenarbeit-Mit-Heidrun-Jung-by-Udo-Jung.pdf
    • http://muicuiu.dumb1.com/1a00a05a09a01a07a09/Nietzsche-s-Zarathustra-Notes-of-the-Seminar-Given-in-1934-1939-C-G-Jung-by-C-G-Jung.pdf
    • http://muicuiu.dumb1.com/1a00a09a09a02a04a02/The-Question-of-Psychological-Types-The-Correspondence-of-C-G-Jung-and-Hans-Schmid-Guisan-1915-1916-by-C-G-Jung.pdf
    • http://muicuiu.dumb1.com/1a01a05a05a01a09a04/Jung-on-Mythology-by-C-G-Jung.pdf
    • http://muicuiu.dumb1.com/9a09a02a08a08/The-Portable-Jung-by-C-G-Jung.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a04a04/Nackt-im-Park-by-Red-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a02/Nackt-Duschen-by-M-C-Hanlon.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a04a05/Niedlich-und-nackt-by-Red-Digital.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a03a04/Male-mich-nackt-by-Alun.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a04/Nackt-amp-Ausgeliefert-by-Anita-Rosenbach.pdf
    • http://muicuiu.dumb1.com/1a00a04a09a03a00a00/Wundersch-n-nackt-und-verspielt-by-SunImage21.pdf
    • http://muicuiu.dumb1.com/9a08a08a01a08a02/NACKT-PERFEKTE-M-DCHEN-4-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a00/NACKT-PERFEKTE-M-DCHEN-13-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a03/NACKT-PERFEKTE-M-DCHEN-3-by-Key-Nudo.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a05a09/Nackt-in-Turnschuhen-by-Tommi-Horwath.pdf
    • http://muicuiu.dumb1.com/9a08a07a09a06a08/Ganz-nackt-Erotische-Storys-by-Luna.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a05a02/Nackt-und-Schamlos-Sexgeschichten-by-Hans-Albers.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a04a07/Amanda-nackt-in-ihrem-Schlafzimmer-by-Red-Digital.pdf