Malicious PDF — malware analysis report

Static analysis result for SHA-256 04184a949d521f6b…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 04:22:21 +01:00 Authoring application: mPDF 5.7
MD5: 8ceb32f985b4c109957bfe24641ef9c6 SHA-1: f37e17853c8d46636e736402d24bbb004644ed7b SHA-256: 04184a949d521f6b2156ee3a742dd3dbabaeb478e24dbc648d0919460fd1095b
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and structure suggest a malicious intent, possibly to manipulate search engine results or to host malicious content disguised as legitimate documents. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a06a03a03a00a03/The-Man-with-Kaleidoscope-Eyes-The-Art-of-Alan-Aldridge-by-Alan-Aldridge.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a03a01/Consumption-by-Alan-Aldridge.pdf
    • http://muicuiu.dumb1.com/6a07a08a05a09/Pop-by-Kitty-Aldridge.pdf
    • http://muicuiu.dumb1.com/3a09a02a09a03a05/Rogues-by-Christy-Aldridge.pdf
    • http://muicuiu.dumb1.com/1a00a01a03a04a08a08/Michaela-by-Sarah-Aldridge.pdf
    • http://muicuiu.dumb1.com/3a02a00a08a06a07/I-Ching-Prescriptions-by-Adele-Aldridge.pdf
    • http://muicuiu.dumb1.com/1a06a03a00a08a03/The-Pharaoh-Contract-The-Emancipator-1-by-Ray-Aldridge.pdf
    • http://muicuiu.dumb1.com/3a02a00a08a07a06/IChing-Womens-Book-of-Changes-by-Adele-Aldridge.pdf
    • http://muicuiu.dumb1.com/1a00a02a04a05a01/The-True-Story-of-Spit-Mac-Phee-by-James-Aldridge.pdf
    • http://muicuiu.dumb1.com/3a06a03a00a06a05/I-Ching-Meditations-A-Womans-Book-of-Changes-by-Adele-Aldridge.pdf
    • http://muicuiu.dumb1.com/7a04a04a08a04/The-True-Story-of-Lilli-Stubeck-by-James-Aldridge.pdf
    • http://muicuiu.dumb1.com/4a04a00a08a03a03/The-Marriage-Pact-Loving-an-Aldridge-1-by-Wendi-Sotis.pdf
    • http://muicuiu.dumb1.com/3a09a02a02a04a04/Alan-Watts-Teaches-Meditation-by-Alan-W-Watts.pdf
    • http://muicuiu.dumb1.com/1a01a06a04a07a09a07/Tamora-Pierce---Knights-of-Tortall-Acton-of-Fenrigh-Alan-of-Pirate-s-Swoop-Alan-of-Trebond-Alanna-of-Pirate-s-Swoop-and-Olau-Alexander-of-Tirragen-Anders-of-Mindelan-Balduin-of-Disart-Cleon-of-Kennan-Conal-of-Mindelan-by-Source-Wikia.pdf
    • http://muicuiu.dumb1.com/1a02a09a05a03a04/Alan-Moore-s-The-Courtyard-by-Alan-Moore.pdf
    • http://muicuiu.dumb1.com/7a06a03a03a00a02/The-Magic-Kaleidoscope-Book-and-Kaleidoscope-by-Sheila-Black.pdf
    • http://muicuiu.dumb1.com/1a03a02a06a06a09/This-Boy-by-Alan-Johnson.pdf
    • http://muicuiu.dumb1.com/1a04a03a00a05a01/Top-10-Vol-1-by-Alan-Moore.pdf
    • http://muicuiu.dumb1.com/3a05a08a03a06a00/Did-we-see-him-by-Alan-Place.pdf
    • http://muicuiu.dumb1.com/1a07a03a09a05/Your-Day-in-the-Barrel-by-Alan-Furst.pdf