Malicious PDF — malware analysis report

Static analysis result for SHA-256 0019fab93e737757…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 04:16:03 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-04
MD5: 35525bf8473fca82ea8d8353809ab7da SHA-1: 717c86af3f8126b224841d4f2d090bffc8ef300f SHA-256: 0019fab93e7377575831e9a4d2f3c5f5c0830b5c56f127208461d16d2ce5d4cc
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm that attempts to disguise malicious content as book downloads. The ML classifier strongly indicated maliciousness, and the heuristic for a PDF link farm confirms this suspicious structure. While no scripts were extracted, the overall pattern suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a03a09a00a02a00/The-Unquiet-Dead-Rachel-Getty-amp-Esa-Khattak-1-by-Ausma-Zehanat-Khan.pdf In PDF document text
    • http://muicuiu.dumb1.com/6a00a06a09a08a09/The-Language-of-Secrets-Rachel-Getty-amp-Esa-Khattak-2-by-Ausma-Zehanat-Khan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a04a07a06a09/Qajar-Dynasty-Aga-Khan-III-Prince-Aly-Khan-Mohammad-Mosaddegh-Aga-Khan-IV-Prince-Sadruddin-Aga-Khan-Marjane-Satrapi-by-Source-Wikipedia.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a05a03a00a05a07/Unquiet-Earth-An-Anthology-of-Living-Dead-Flash-Fiction-by-Chris-Bartholomew.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a07a07a07a07a07/Dead-Man-Stalking-The-Morganville-Vampires-4-5-by-Rachel-Caine.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a03a08a02a09a09/The-Life-s-Too-Short-New-Writing-from-Pakistan-Edited-by-Faiza-S-Khan-Aysha-Raja-by-Faiza-S-Khan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a09a04a03a06/The-Dead-Girls-Dance-Morganville-Vampires-2-by-Rachel-Caine.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a09a07a04/The-Dead-Girls-Dance-The-Morganville-Vampires-2-by-Rachel-Caine.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a04a04a09a09a04/The-Chaka-Khan-Songbook-Piano-Vocal-Guitar-by-Chaka-Khan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a08a01a07a01/Making-Architecture-The-Getty-Center-by-Harold-M-Williams.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a09a06a08a00/Kidnapped-The-Tragic-Life-of-J-Paul-Getty-III-by-Charles-Fox.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a09a05a03a06a07/The-Hulton-Getty-Picture-Collection-1930-s-by-Nick-Yapp.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a05a02a04a05a00/The-Unquiet-Grave-by-Sharyn-McCrumb.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a02a09a05a08a03/True-Blood-Omnibus-2-Dead-to-the-World-Dead-as-a-Doornail-Definitely-Dead-Sookie-Stackhouse-4-6-by-Charlaine-Harris.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a02a01a07a05/The-Unquiet-Heart-Danny-McRae-2-by-Gordon-Ferris.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a03a03a05a02/Edward-Lansdale-The-Unquiet-American-by-Cecil-B-Currey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a02a02a08a08/The-Unquiet-Grave-Damen-Brook-4-by-Steven-Dunne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a04a06a08a08a07/Unquiet-Slumber-Blue-Fire-1-by-Paulette-Miller.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a08a00a09a05a08/The-Unquiet-Ones-A-History-of-Pakistan-Cricket-by-Osman-Samiuddin.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a08a04a09a04a03/Echoes-of-Silence-Unquiet-Mind-1-by-Anne-Malcom.pdfIn PDF document text