Malicious PDF — malware analysis report

Static analysis result for SHA-256 fee57204c52d4a61…

MALICIOUS

PDF

22.9 KB Created: 2019-04-29 23:00:41 +01:00 Authoring application: mPDF 5.7
MD5: 715dbf38d3107fcb716824e73857f44d SHA-1: ba4fcaad11acc1361c6ef069ad20398773f06599 SHA-256: fee57204c52d4a61a53b6d7ff3b372564cd096eb2bc397d5b345a691b012ae76
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on the domain muicuiu.dumb1.com. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample, limiting the analysis of direct execution behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a07a06a06a01a08/Fire-Arrow-by-Franklin-Allen-Leib.pdf
    • http://muicuiu.dumb1.com/9a07a06a06a07a09/Valley-of-the-Shadow-by-Franklin-Allen-Leib.pdf
    • http://muicuiu.dumb1.com/9a07a06a07a05a06/The-House-of-Pain-by-Franklin-Allen-Leib.pdf
    • http://muicuiu.dumb1.com/4a03a03a07a04a06/Dante-s-Infernal-Guide-to-Your-School-by-Franklin-Allen-Behrens.pdf
    • http://muicuiu.dumb1.com/1a06a04a06a03a08/Fire-Lord-Tales-of-the-Taormin-2-by-Cheryl-J-Franklin.pdf
    • http://muicuiu.dumb1.com/1a00a03a08a07a08a01/Liberty-The-Statue-And-The-American-Dream-by-Leslie-Allen.pdf
    • http://muicuiu.dumb1.com/6a01a06a03a00a04/The-Autobiography-of-Benjamin-Franklin-Complete-Prepared-for-Use-in-Schools-with-Introduction-Notes-and-a-Supplementary-Sketch-Concuding-the-Story-of-Franklin-s-Life-Presented-Mainly-in-His-Own-Words-by-Benjamin-Franklin.pdf
    • http://muicuiu.dumb1.com/1a04a05a04a02a05/Daring-to-Dream-Holding-the-Dream-Finding-the-Dream-Dream-trilogy-1-3-by-Nora-Roberts.pdf
    • http://muicuiu.dumb1.com/4a08a04a01a00/A-Dream-of-Spring-A-Song-of-Ice-and-Fire-7-by-George-R-R-Martin.pdf
    • http://muicuiu.dumb1.com/8a06a03a01a02/Novels-by-Chris-D-lacey-The-Fire-Eternal-Fire-Star-the-Fire-Within-Icefire-the-Last-Dragon-Chronicles-Fire-World-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/9a08a04a00/Franklin-Barbecue-A-Meat-Smoking-Manifesto-by-Aaron-Franklin.pdf
    • http://muicuiu.dumb1.com/1a00a01a06a07a03a06/Shakespeare-s-Insomnia-and-the-Causes-Thereof-by-Franklin-H-Franklin-Harvey-Head.pdf
    • http://muicuiu.dumb1.com/8a00a07a01a00a01/Benjamin-Franklin-My-Autobiography-The-Editions-Artisan-Devereaux-Classic-Literature-Series-by-Benjamin-Franklin.pdf
    • http://muicuiu.dumb1.com/5a03a05a04a03a05/Franklin-Says-Sorry-Franklin-TV-02-by-Paulette-Bourgeois.pdf
    • http://muicuiu.dumb1.com/4a05a03a03a01a03/Benjamin-Franklin-and-a-Case-of-Christmas-Murder-Benjamin-Franklin-2-by-Robert-Lee-Hall.pdf
    • http://muicuiu.dumb1.com/7a03a00a01a03a01/Benjamin-Franklin-His-Autobiography-With-a-Narrative-of-His-Public-Life-and-Services-by-Benjamin-Franklin.pdf
    • http://muicuiu.dumb1.com/8a00a09a04a07a06/The-Autobiography-of-Benjamin-Franklin-illustrated-Supreme-Edition-by-Benjamin-Franklin.pdf
    • http://muicuiu.dumb1.com/3a07a03a00a03a01/The-Negative-s-Tale-by-R-Leib.pdf
    • http://muicuiu.dumb1.com/9a07a02a09a05/Allen-K-s-Inhuman-Magazine-Issue-5-Fall-2011-by-Allen-Koszowski.pdf
    • http://muicuiu.dumb1.com/3a06a09a00a05a02/Fierce-Family-by-Bart-R-Leib.pdf
    • http://muicuiu.dumb1.com/1a04a05a04a02a05/Daring-to-Dream-Holding-the-Dream-