Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcb1291f937675c7…

MALICIOUS

PDF

29.9 KB Created: 2019-04-30 04:25:36 +01:00 Authoring application: mPDF 5.7
MD5: 32c09ff707d24522860cc6d43ce544b0 SHA-1: 5dd15db9af6f18777003ef2db36b8faf8468388c SHA-256: fcb1291f937675c7fdeed7b754afeb2053db3f278b68c2a97589354ab77c5112
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this as malicious with high confidence. The primary attack pattern appears to be SEO poisoning or a link farm designed to drive traffic to potentially malicious content hosted on the 'muicuiu.dumb1.com' domain. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9689

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a00a06a06a02a00/World-History-Biographies-Anne-Frank-The-Young-Writer-Who-Told-the-World-Her-Story-by-Ann-Kramer.pdf
    • http://muicuiu.dumb1.com/8a02a01a04a07a03/Man-the-story-of-his-advent-life-and-development-in-the-earth-world-and-his-continued-life-and-progression-in-the-spirit-world-with-a-description-allegory-of-his-principal-aids-and-counsellors-told-in-epic-verse-by-Edwy-Wells-Foster.pdf
    • http://muicuiu.dumb1.com/2a07a05a07a09a02/This-Is-Not-a-Writing-Manual-Notes-for-the-Young-Writer-in-the-Real-World-by-Kerri-Majors.pdf
    • http://muicuiu.dumb1.com/2a07a05a07a01a01/Anne-Frank-The-Diary-of-a-Young-Girl-by-Anne-Frank.pdf
    • http://muicuiu.dumb1.com/2a05a07a05a03a04/Building-the-World-An-Encyclopedia-of-the-Great-Engineering-Projects-in-History-Volume-1-by-Frank-Davidson.pdf
    • http://muicuiu.dumb1.com/1a00a00a04a09a00a04/Interactive-Cengage-Learing-eBook-World-History-Resource-Center-Instant-Access-Code-for-Duiker-Spielvogel-s-The-Essential-World-History-by-William-J-Duiker.pdf
    • http://muicuiu.dumb1.com/4a00a02a04a01a01/A-World-at-Arms-A-Global-History-of-World-War-II-by-Gerhard-L-Weinberg.pdf
    • http://muicuiu.dumb1.com/2a02a09a06a06a02/Study-Guide-For-Anne-Frank-Remembered-The-Story-Of-The-Woman-Who-Helped-To-Hide-The-Frank-Family-With-Related-Readings-by-Miep-Gies.pdf
    • http://muicuiu.dumb1.com/4a04a01a00a09a08/The-Diary-of-a-Young-Girl-by-Anne-Frank.pdf
    • http://muicuiu.dumb1.com/9a08a01a07a04/The-Diary-of-a-Young-Girl-by-Anne-Frank.pdf
    • http://muicuiu.dumb1.com/2a08a06a04a09a01/The-Man-Who-Told-the-World-Sing-Out-3-by-Hanna-Dare.pdf
    • http://muicuiu.dumb1.com/9a06a05a07a03a06/All-Quiet-On-The-Western-Front-Erich-Maria-Remarque-World-War-I-History-In-Literature-The-Story-Behind-by-Peter-Guti-rrez.pdf
    • http://muicuiu.dumb1.com/7a07a05a07a07a05/Learning-to-Be-Human-Again-Do-you-remember-who-you-were-before-the-world-told-you-who-you-should-be-by-Matt-Landry.pdf
    • http://muicuiu.dumb1.com/1a09a05a08a07a03/The-Trials-of-a-Scold-The-Incredible-True-Story-of-Writer-Anne-Royall-by-Jeff-Biggers.pdf
    • http://muicuiu.dumb1.com/1a03a09a07a02a08/Hurlbut-s-Story-of-the-Bible-for-Young-and-Old-A-continuous-narrative-of-the-Scriptures-told-in-one-hundred-sixty-eight-stories-by-Jesse-Lyman-Hurlbut.pdf
    • http://muicuiu.dumb1.com/1a01a01a02a04a04a06/Anne-Frank-s-Tales-from-the-Secret-Annex-A-Collection-of-Her-Short-Stories-Fables-and-Lesser-Known-Writings-by-Anne-Frank.pdf
    • http://muicuiu.dumb1.com/2a02a09a03a03a07/Anne-Frank-s-Story-by-Carol-Ann-Lee.pdf
    • http://muicuiu.dumb1.com/3a00a05a04a03/Where-Did-the-Sun-Go-Myths-and-Legends-of-Solar-Eclipses-Around-the-World-Told-with-Poetry-and-Puppetry-by-Janet-Cameron-Hoult.pdf
    • http://muicuiu.dumb1.com/4a05a02a01a03a05/The-Last-Seven-Months-Of-Anne-Frank---The-Stories-of-Six-Women-Who-Knew-Anne-Frank-by-Willy-Lindwer.pdf
    • http://muicuiu.dumb1.com/4a04a04a05a00a09/Anne-Frank-The-Anne-Frank-House-Authorized-Graphic-Biography-by-Sid-Jacobson.pdf
    • http://muicuiu.dumb1.com/2a07a05a07a09a02/This-Is-Not-a-Writing-Manual-Notes-for-the-Young-Writer-in-the-Real-World-by-Ker