Malicious PDF — malware analysis report

Static analysis result for SHA-256 04358d5c6ab092ac…

MALICIOUS

PDF

19.1 KB Created: 2019-04-30 03:50:09 +01:00 Authoring application: mPDF 5.7
MD5: 778e5e700028598abcf70376bbf501b1 SHA-1: 854e4e930be182f117368468d6821acd79130eb9 SHA-256: 04358d5c6ab092acd63ea2077d807caad9a711567a03d706df5711fff3e92cf9
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, masquerading as book downloads. The heuristic PDF_SEO_LINK_FARM indicates a link farm designed to attract users with seemingly legitimate book titles. While the URLs themselves are marked as confirmed benign, the sheer volume and the heuristic firing suggest a malicious intent to drive traffic or potentially deliver further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a02a06a04a05a05/Basic-Cannabis-Cooking-Basic-Cooking-with-Cannabis-Book-1-by-Steven-Frobe.pdf
    • http://muicuiu.dumb1.com/5a05a03a04a08a06/Life-Is-a-Gift-The-Zen-of-Bennett-by-Tony-Bennett.pdf
    • http://muicuiu.dumb1.com/1a00a02a02a02a08a05/Cannabis-and-Cannabinoids-by-Franjo-Grotenhermen.pdf
    • http://muicuiu.dumb1.com/8a02a06a08a08a06/Brave-New-Weed-Adventures-into-the-Uncharted-World-of-Cannabis-by-Joe-Dolce.pdf
    • http://muicuiu.dumb1.com/8a06a01a06a00a05/AUSBRUCH-mit-Kaffeekr-nzchen-Kunstraub-amp-Cannabis-Seniorenschiff-auf-Reisen-1-by-Waltraud-Kirschke.pdf
    • http://muicuiu.dumb1.com/1a00a02a02a01a07a05/Cannabis-and-Cannabinoids-Pharmacology-Toxicology-and-Therapeutic-Potential-by-Franjo-Grotenhermen.pdf
    • http://muicuiu.dumb1.com/7a05a09a03a01a02/The-Official-Pot-Co-Cannabis-Wholesale-Superstore-Coloring-Book-by-Bumpa-Gump.pdf
    • http://muicuiu.dumb1.com/1a01a07a04a01a09a01/Soma-by-Tao-Han.pdf
    • http://muicuiu.dumb1.com/5a05a03a04a08a03/The-Secret-Life-of-Cooper-Bennett-Cooper-Bennett-1-by-Golden-Czermak.pdf
    • http://muicuiu.dumb1.com/1a01a07a00a03a00a02/Keine-Angst-vor-Hanf-Warum-Cannabis-legalisiert-werden-muss-by-Mathias-Br-ckers.pdf
    • http://muicuiu.dumb1.com/1a01a07a04a01a09a06/Soma-s-Metamorphoses-by-Jan-Gonda.pdf
    • http://muicuiu.dumb1.com/1a01a07a03a08a00a08/Soma-by-Jason-Gurley.pdf
    • http://muicuiu.dumb1.com/1a01a02a01a06a05a02/Heart-of-Dankness-Underground-Botanists-Outlaw-Farmers-and-the-Race-for-the-Cannabis-Cup-by-Mark-Haskell-Smith.pdf
    • http://muicuiu.dumb1.com/8a07a00a04a03/The-Emperor-Wears-No-Clothes-The-Authoritative-Historical-Record-of-Cannabis-and-the-Conspiracy-Against-Marijuana-by-Jack-Herer.pdf
    • http://muicuiu.dumb1.com/9a03a08a07a04a01/Bestie-da-soma-by-Alfredo-Mogavero.pdf
    • http://muicuiu.dumb1.com/1a01a03a02a00a07a09/Idylle-in-ballingschap-by-Soma-Morgenstern.pdf
    • http://muicuiu.dumb1.com/1a01a07a04a01a02a00/Voice-Psyche-and-Soma-by-Corneluis-L-Reid.pdf
    • http://muicuiu.dumb1.com/7a06a03a09a06a06/Lord-Kito-s-Revenge-by-Soma-Vira.pdf
    • http://muicuiu.dumb1.com/1a01a07a03a09a07a02/Blue-Tide-The-Search-for-Soma-by-Mike-Jay.pdf
    • http://muicuiu.dumb1.com/1a01a07a04a02a00a03/Royal-Mughal-Ladies-And-their-Contribution-by-Soma-Mukherjee.pdf