Malicious PDF — malware analysis report

Static analysis result for SHA-256 06b5c3ffa0a61f77…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 04:24:26 +01:00 Authoring application: mPDF 5.7
MD5: 1c195f313b2c44ad8aa09db178432f47 SHA-1: b0f5065a353e6511d0b69c9fb5fcc9f56b8c8aaf SHA-256: 06b5c3ffa0a61f77014af51dc8106b9415f6e606e8a2c51684fbd94edfe4500b
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm, suggesting an attempt to direct users to malicious content. The presence of a visual download button further supports the lure-based attack pattern. While the ML classifier strongly indicates maliciousness, the specific payload or ultimate goal beyond link distribution is not clear from the available evidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a08a07a04a05a05/Dior-New-Looks-by-Jerome-Gautier.pdf
    • http://muicuiu.dumb1.com/5a06a09a00a04a06/Humorous-World-of-Jerome-K-Jerome-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a06a09a00a04a01/Jerome-K-Jerome-Collected-Works-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a06a08a00a02a09/The-Works-of-Theophile-Gautier-Volume-5-The-Romance-of-a-Mummy-and-Egypt-by-Th-ophile-Gautier.pdf
    • http://muicuiu.dumb1.com/5a06a08a01a00a07/The-Works-of-Theophile-Gautier-Volume-15-by-Th-ophile-Gautier.pdf
    • http://muicuiu.dumb1.com/8a06a05a04a03a06/Drei-Mann-in-einem-Boot-Ganz-zu-schweigen-vom-Hund-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/9a03a00a09a06a05/Drei-Mann-in-einem-Boot-vom-Hunde-ganz-zu-schweigen-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/6a00a01a05a06a08/Three-Men-in-a-Boat-To-Say-Nothing-of-the-Dog-New-Illustrated-Edition-with-67-Original-Drawings-by-A-Frederics-a-Detailed-Map-of-Tour-and-a-Photo-of-the-Three-Men-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/7a03a02a04a04a04/The-Soul-of-Nicholas-Snyders-Or-the-Miser-of-Zandam-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a05a04a01a04a05/Tres-hombres-en-una-barca-por-no-mencionar-al-perro-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a02a07a00a05a00/Trois-hommes-dans-un-bateau-Annot-Livre-bilingue-Apprendre-l-anglais-en-lisant-Book-18-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/1a01a02a06a06a05a00/Three-Men-in-a-Boat-To-Say-Nothing-of-the-Dog-Illustrated-1889-edition-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a02a08a08a00a01/Trois-Hommes-Dans-Un-Bateau-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/6a02a09a05a03a04/Trois-hommes-dans-un-bateau-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/5a06a09a00a03a00/Second-Thoughts-Of-An-Idle-Fellow-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/7a04a08a05a02a05/Dior---Set-of-3-by-Assouline-Publishing.pdf
    • http://muicuiu.dumb1.com/7a04a08a02a07a07/American-Dior-by-Assouline-Publishing.pdf
    • http://muicuiu.dumb1.com/5a06a07a08a01a01/5-Stories-by-Theophile-Gautier-by-Th-ophile-Gautier.pdf
    • http://muicuiu.dumb1.com/8a02a02a03a08a03/Idle-Thoughts-of-an-Idle-Fellow-A-Humourous-Take-on-Mundane-Topics-Aziloth-Books-by-Jerome-K-Jerome.pdf
    • http://muicuiu.dumb1.com/1a00a09a01a04a04a02/Tre-uomini-in-barca-by-Jerome-K-Jerome.pdf