Malicious PDF — malware analysis report

Static analysis result for SHA-256 f630ad6e7bd654bd…

MALICIOUS

PDF

21.3 KB Created: 2019-04-29 23:12:55 +01:00 Authoring application: mPDF 5.7
MD5: be8b79ba5047764775eabfd542de77c2 SHA-1: b8c0f61b40b0f3b4db40315c7ea6fde873868096 SHA-256: f630ad6e7bd654bde42ce35c4ac8188fcce63a44c56dc8479660cf6902fe74b8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain 'muicuiu.dumb1.com'. This behavior is indicative of a link farm or a phishing lure designed to redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a01a07a07a08/When-I-Was-a-Child-I-Read-Books-Essays-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/1a08a06a03a07a09/Gilead-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/4a05a01a08a09a07/Gilead-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/4a06a00a06a03a05/Housekeeping-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/5a05a07a01a09/Housekeeping-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/3a04a00a04a02a05/Home-Gilead-2-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/1a05a01a04a02/Mother-Country-Britain-the-Welfare-State-and-Nuclear-Pollution-by-Marilynne-Robinson.pdf
    • http://muicuiu.dumb1.com/2a03a08a04a08a00/The-Book-of-Lost-Books-An-Incomplete-History-of-All-the-Great-Books-You-ll-Never-Read-by-Stuart-Kelly.pdf
    • http://muicuiu.dumb1.com/4a08a08a03a05a09/The-Green-Child-by-Herbert-Read.pdf
    • http://muicuiu.dumb1.com/2a09a07a06a05a04/The-Books-You-Read-by-Charles-E-Jones.pdf
    • http://muicuiu.dumb1.com/1a01a05a03a07a01a06/Read-Real-Japanese-Essays-Contemporary-Writings-by-Popular-Authors-by-Janet-Ashby.pdf
    • http://muicuiu.dumb1.com/3a03a07a04a02a03/You-Your-Child-and-School-Navigate-Your-Way-to-the-Best-Education-by-Ken-Robinson.pdf
    • http://muicuiu.dumb1.com/2a04a09a00a04a05/Why-I-Read-The-Serious-Pleasure-of-Books-by-Wendy-Lesser.pdf
    • http://muicuiu.dumb1.com/2a06a07a05a02a09/The-Little-Guide-to-Your-Well-Read-Life-How-to-Get-More-Books-in-Your-Life-and-More-Life-from-Your-Books-by-Steve-Leveen.pdf
    • http://muicuiu.dumb1.com/2a05a01a03a07a04/10-Books-Every-Conservative-Must-Read-Plus-Four-Not-to-Miss-and-One-Impostor-by-Benjamin-Wiker.pdf
    • http://muicuiu.dumb1.com/3a04a02a05a06a08/Abridged-Classics-Brief-Summaries-of-Books-You-Were-Supposed-to-Read-but-Probably-Didn-t-by-John-Atkinson.pdf
    • http://muicuiu.dumb1.com/2a05a06a07a01a04/How-Two-Gerbils-Twenty-Goldfish-Two-Hundred-Games-Two-Thousand-Books-and-I-Taught-Them-How-to-Read-by-Steven-Daniels.pdf
    • http://muicuiu.dumb1.com/3a03a08a02a03a04/The-Great-American-Read-The-Book-of-Books-Explore-America-s-100-Best-Loved-Novels-by-Jessica-Allen.pdf
    • http://muicuiu.dumb1.com/4a07a02a04a07/Blessed-Child-The-Caleb-Books-1-by-Ted-Dekker.pdf
    • http://muicuiu.dumb1.com/1a09a06a04a03a05/Lee-Child-s-Jack-Reacher-Books-1-6-With-Prose-Translations-Jack-Reacher-1-6-by-Lee-Child.pdf
    • http://muicuiu.dumb1.com/2a09a07a06a05a04/The-Books-You-Read-by-C