Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e2ac2d75c4cf69…

MALICIOUS

PDF

17.2 KB Created: 2019-05-07 07:47:42 +01:00 Authoring application: mPDF 5.7
MD5: ad98f8d1a462f9085294468499f4e0b5 SHA-1: 946d25ff9f15399a523c8a520ade3af67ec9b8df SHA-256: 04e2ac2d75c4cf69286fb39118f916bfd085ed444d9ae7182b5f5632c1a1a664
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, possibly to distribute malware or engage in SEO abuse. The presence of a 'download' button lure further supports a deceptive purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a04a09a08a06a06/Le-Vol-de-l-Aigle-I-L-re-des-conqu-rants-by-M-L-Versini.pdf
    • http://muicuiu.dumb1.com/9a03a08a08a02a03/BESTIE-II-by-sergio-versini.pdf
    • http://muicuiu.dumb1.com/4a03a03a04a09a07/But-Then-Again-I-Could-Be-Wrong-The-Book-of-Rants-by-Jim-Rising.pdf
    • http://muicuiu.dumb1.com/6a01a01a01a01/Six-Packs-Rants-And-Midnight-Chants-by-Thornfellow.pdf
    • http://muicuiu.dumb1.com/5a02a09a01a07a09/Not-That-You-Asked-Rants-Exploits-and-Obsessions-by-Steve-Almond.pdf
    • http://muicuiu.dumb1.com/4a06a00a04a09a02/Rants-in-the-Dark-From-One-Tired-Mama-to-Another-by-Emily-Writes.pdf
    • http://muicuiu.dumb1.com/6a03a05a06a07a07/Aigle-by-Aziz-Chouaki.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a03a03/One-Butt-Cheek-at-a-Time-Gert-Garibaldi-s-Rants-and-Raves-1-by-Amber-Kizer.pdf
    • http://muicuiu.dumb1.com/5a06a08a04a01a00/L-aigle-gyptien-Nasser-by-Gilbert-Sinou-.pdf
    • http://muicuiu.dumb1.com/6a03a05a07a06a00/Ultima-fermata-in-Paradiso-by-Antonella-Aigle.pdf
    • http://muicuiu.dumb1.com/1a03a05a09a02a09/Broken-Fated-Saga-4-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://muicuiu.dumb1.com/7a09a09a00a07/Shifting-Fated-Saga-2-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://muicuiu.dumb1.com/1a01a05a00a03a00a02/Witches-of-The-Demon-Isle-Box-Set-Volumes-1-3-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://muicuiu.dumb1.com/7a08a00a09a06/Wicked-Werewolves-The-Demon-Isle-Witches-2-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://muicuiu.dumb1.com/7a08a07a00a01/Ghostly-Guardian-The-Demon-Isle-Witches-1-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://muicuiu.dumb1.com/5a04a05a08a08a06/L-Aigle-et-la-Salamandre-Tome-1-Naissance-dans-le-brasier-by-Antoine-Piatzszek.pdf
    • http://muicuiu.dumb1.com/2a03a08a07a00a02/Gluten-Is-My-Bitch-Rants-Recipes-and-Ridiculousness-for-the-Gluten-Free-by-April-Peveteaux.pdf
    • http://muicuiu.dumb1.com/8a01a01a02a03a08/AI-Weiwei-s-Blog-Writings-Interviews-and-Digital-Rants-2006-2009-by-Ai-Weiwei.pdf
    • http://muicuiu.dumb1.com/6a09a04a08a02a03/Airlines-of-France-Air-France-Openskies-Aigle-Azur-XL-Airways-France-Corsairfly-Regional-Compagnie-Aerienne-Europeenne-by-Source-Wikipedia.pdf