Malicious PDF — malware analysis report

Static analysis result for SHA-256 001934c920baccf5…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 05:11:34 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-04
MD5: 921f75daa4783b02f871237c5681de64 SHA-1: 6220d88bca791af0291592fe9aaf89a773ca5a14 SHA-256: 001934c920baccf55dad879cc7e3cb179754cc39be89beffc6e91b041b886866
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm, suggesting an attempt to manipulate search engine results or redirect users to malicious content. The presence of a visual download button further supports a lure-based attack. While the specific payload is not clear, the ML classifier strongly indicates malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a09a04a07a05a04/A-Guide-to-Persepolis-1-and-2-or-The-Complete-Persepolis-by-Marjane-Satrapi-by-Liss-Ross.pdf In PDF document text
    • http://muicuiu.dumb1.com/3a05a08a00a09/Persepolis-2-The-Story-of-a-Return-Persepolis-2-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a01a08a01/Persepolis-The-Story-of-a-Childhood-Persepolis-1-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a04a07a01a06/Quicklet-on-Marjane-Satrapi-s-Persepolis-by-Natacha-Pavlov.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a08a09a02a03a03/Persepolis-The-Story-of-a-Childhood-and-the-Story-of-a-Return-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a02a03a00a05a01/Persepolis-The-Story-of-a-Childhood-and-The-Story-of-a-Return-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a06a00a05/100-Provocative-Statements-about-the-Complete-Persepolis-by-Ethan-Orek.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a00a07a07a09a09/A-Guide-to-The-Book-Thief-by-Markus-Zusak-by-Liss-Ross.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a06a09a03a04a07/Embroideries-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a06a03a07a06a01/Chicken-with-Plums-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a03a03a00a04a05/Chicken-with-Plums-by-Marjane-Satrapi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a04a08a09/Persepolis-2-0-by-Payman.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a04a09a07/The-Persepolis-Affair-by-Veronica-Platzer.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a04a09a09/Persepolis-Discovery-and-Afterlife-of-a-World-Wonder-by-Ali-Mousavi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a05a09a03/The-Extra-Credit-Society-by-Hera-Persepolis.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a05a09a07/Amazon-Planet-3-Master-and-Slave-by-Hera-Persepolis.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a05a09a08/Amazon-Planet-2-Trained-as-a-Sex-Slave-by-Hera-Persepolis.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a05a09a02/Amazon-Planet-6-Transforming-the-Futa-by-Hera-Persepolis.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a05a06a08/Amazon-Planet-4-Slave-to-the-Queen-by-Hera-Persepolis.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a00a06a00a02/Festival-of-Arts-Shiraz-Persepolis-1970-by-Vali-Mahlouji.pdfIn PDF document text