Malicious PDF — malware analysis report

Static analysis result for SHA-256 04642e4b37a26682…

MALICIOUS

PDF

19.7 KB Created: 2019-05-02 01:22:38 +01:00 Authoring application: mPDF 5.7
MD5: ea0ffbffa1c5158da158f7b192946e97 SHA-1: b8f7df7f1bc63eb45048e9e55776ea5ef7a46b3d SHA-256: 04642e4b37a2668290dab00d58e5bf0b522aa4d92a684eb45c76cd5ea1169056
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated and unreadable, the presence of numerous links suggests an attempt to manipulate search engine results or distribute content through a link farm. The ML classifier also flagged the PDF as malicious. No scripts were extracted from this sample, limiting the ability to determine a more specific attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a06a03a01a04a02/Jurassic-Park-The-Lost-World-The-Junior-Novelization-by-Gail-Herman.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a06a00/Jurassic-Park-Michael-Crichton-List-of-Jurassic-Park-Characters-the-Lost-World-Jurassic-Park-Jurassic-Park-III-Biological-Issue-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a08a07a06/Jurassic-World-Fallen-Kingdom-The-Junior-Novelization-by-David-Lewman.pdf
    • http://muicuiu.dumb1.com/5a00a02a03a01/Jurassic-Park-The-Lost-World-Jurassic-Park-1-2-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/1a03a07a06a01a00/Jurassic-World-Jurassic-Park-The-Lost-World-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/4a00a07a02a03a00/Pirates-of-the-Caribbean-At-World-s-End-The-Junior-Novelization-by-Tui-T-Sutherland.pdf
    • http://muicuiu.dumb1.com/9a09a04a01a09a00/The-Michael-Crichton-Collection-Jurassic-Park-The-Lost-World-The-Andromeda-Strain-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/2a04a00a05a00a09/Trolls-Junior-Novelization-by-Scholastic-Inc-.pdf
    • http://muicuiu.dumb1.com/5a06a04a04a06a00/Coco-The-Junior-Novelization-by-Angela-Cervantes.pdf
    • http://muicuiu.dumb1.com/6a07a01a07a09a00/Pirates-of-the-Caribbean-On-Stranger-Tides-The-Junior-Novelization-by-James-Ponti.pdf
    • http://muicuiu.dumb1.com/4a09a03a09a07a03/Pirates-of-the-Caribbean-The-Curse-of-the-Black-Pearl-The-Junior-Novelization-by-Irene-Trimble.pdf
    • http://muicuiu.dumb1.com/9a07a01a03a00a04/Captain-America-The-Winter-Soldier-The-Secret-Files-Junior-Novelization-by-Tomas-Palacios.pdf
    • http://muicuiu.dumb1.com/3a04a00a00a07a08/Star-Wars-Episode-V-The-Empire-Strikes-Back-Junior-Novelization-by-Ryder-Windham.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a05a07/The-Dinosaurs-Of-Jurassic-Park-by-Wendy-Larson.pdf
    • http://muicuiu.dumb1.com/6a05a06a07a01a08/Jurassic-Park-and-Congo-by-Michael-Crichton.pdf
    • http://muicuiu.dumb1.com/1a01a06a03a01a04a00/Jurassic-Park-Piano-Solos-by-John-Williams.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a06a03/Jurassic-Park-easy-piano-by-John-Williams.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a06a05/Flyers-Jurassic-Park-Adventures-3-by-Scott-Ciencin.pdf
    • http://muicuiu.dumb1.com/1a01a06a03a01a04a09/Jurassic-Park-Film-Storybook-by-Jane-B-Mason.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a09a05a05/Prey-Jurassic-Park-Adventures-2-by-Scott-Ciencin.pdf