Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe76835e6a4fe393…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 04:33:06 +01:00 Authoring application: mPDF 5.7
MD5: 9415a15fc14f880c78f0d87a8b71482e SHA-1: 82a110d45af49dc836015d3129280303934b58b4 SHA-256: fe76835e6a4fe393f0097760c58723c5fa82ad6b7bc625127eb7525b140440a0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'muicuiu.dumb1.com'. This suggests a link farm or redirection tactic to distribute malicious content or phish for credentials. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a05a06a03a02a01/Global-Trends-Shaping-The-Workplace-Of-Tomorrow-C-By-Maureen-Minehan-Nathaniel-M-Semple-William-T-Semple-by-Maureen-Minehan.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a00a05/Semple-Math-Level-1-Teacher-s-Manual-by-Janice-L-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a01a06/Semple-Math-Wkbk-A-Level-1-by-Janice-L-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a01a08/Semple-Math-Level-2-by-Janice-L-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a08a06/AIMEE-The-Life-Story-of-Aimee-Semple-McPherson-by-Aimee-Semple-McPherson.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a03a09/The-Relationship-by-Rob-Semple.pdf
    • http://muicuiu.dumb1.com/1a07a09a00a00a01/Where-d-You-Go-Bernadette-by-Maria-Semple.pdf
    • http://muicuiu.dumb1.com/6a00a02a04a08/Where-d-You-Go-Bernadette-by-Maria-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a04a05/This-Is-That-by-Aimee-Semple-McPherson.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a01a05/Phylogenetics-by-Charles-Semple.pdf
    • http://muicuiu.dumb1.com/2a01a03a00a00a03/Where-d-You-Go-Bernadette-by-Maria-Semple.pdf
    • http://muicuiu.dumb1.com/4a01a07a07/Today-Will-Be-Different-by-Maria-Semple.pdf
    • http://muicuiu.dumb1.com/2a05a06a01a07a08/Where-d-You-Go-Bernadette-by-Maria-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a01a08/Diary-of-a-Connecticut-Yogi-by-J-J-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a07a08/King-Kong-by-Lorenzo-Semple-Jr-.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a01a03/Algebraic-Projective-Geometry-by-J-G-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a02a02/Chasing-Happy-by-Laurene-Bobb-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a05a04/The-Rector-Who-Wouldn-t-Pray-for-Rain-by-Pat-Semple.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a02a04a08/Lectures-in-Memory-of-Louise-Taft-Semple-by-D-W-Bradeen.pdf
    • http://muicuiu.dumb1.com/1a01a05a06a03a01a07/Zos-Kia-An-Introductory-Essay-On-The-Art-And-Sorcery-Of-Austin-Osman-Spare-by-Gavin-W-Semple.pdf