Malicious PDF — malware analysis report

Static analysis result for SHA-256 07bc631a201ec27a…

MALICIOUS

PDF

24.5 KB Created: 2019-05-02 00:50:22 +01:00 Authoring application: mPDF 5.7
MD5: e0498b0dde5b3e48bb66bdda21e1769c SHA-1: 77d765f8a703961e64b2de81aee374a6ba9ad4bc SHA-256: 07bc631a201ec27a850840a4a24d335143e67e48d88456756a956cc6023a02ed
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to external PDF files, indicating a link farm. The presence of a 'download button' heuristic suggests a lure to encourage users to click these links. While the document body is heavily obfuscated, the overall structure and heuristic firings point towards a phishing or malicious download attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a05a01a01a09a00/Voltaire-10-Romane-u-a-Candide-Die-Prinzessin-von-Babylon-Mikromegas-Skarmentados-Reisen-Der-Wei-e-und-der-Schwarze-Wie-s-in-der-Welt-geht-Jeannot-Colin-Der-Hurone-Zadig-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a08a02a07a08a08/Voltaire-s-Candide-and-the-Critics-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/7a05a01a01a09a03/Works-of-Voltaire-20-works-Candide-Zadig-Philosophical-Dictionary-selected-poetry-amp-more-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a08a02a06a03a07/Candide-and-Other-Works-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/1a00a04a01a08a09a02/Candide-with-eBook-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/8a03a04a07a01a05/Candide-The-best-of-all-possible-worlds-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/3a01a04a06a06a05/Candide-and-Zadig-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/9a01a02a03a05/Candide-or-Optimism-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a08a02a08a03a03/Candide-Or-the-Optimist-And-Other-Romances-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/1a00a04a06a01a06a00/Candide-oder-der-Optimismus-by---Voltaire.pdf
    • http://muicuiu.dumb1.com/6a01a09a04a02a09/Candide-and-Philosophical-Letters-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a08a02a06a03a03/Voltaire-s-Adventures-Before-Candide-by-Martin-D-Gibbs.pdf
    • http://muicuiu.dumb1.com/7a05a01a01a08a07/Romances-Tales-and-Smaller-Pieces-of-M-de-Voltaire-Vol-1-of-2-Zadig-The-World-as-It-Goes-Micromegas-The-White-Bull-Travels-of-Scaramentado-How-Far-We-Ought-to-Impose-Upon-the-People-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/7a05a01a01a03a08/Fiche-de-lecture-Zadig-de-Voltaire-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a01a09a05a08a07/Memoirs-of-the-Life-of-Monsieur-de-Voltaire-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/7a00a02a06a01a09/VOLTAIRE-S-TRAGEDIES-20-Plays-in-One-Volume-Merope-Caesar-Olympia-The-Orphan-of-China-Brutus-Amelia-Oedipus-Mariamne-Socrates-Zaire-Orestes-Nanine-The-Prude-The-Tatler-and-more-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/7a07a09a08a05a06/A-Treatise-on-Toleration-The-Ignorant-Philosopher-And-a-Commentary-on-the-Marquis-of-Becaria-s-Treatise-on-Crimes-and-Punishments-Translated-from-the-Last-Geneva-Edition-of-Mr-de-Voltaire-by-the-REV-David-Williams-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a01a09a04a08a01/Works-of-Voltaire-by-Voltaire.pdf
    • http://muicuiu.dumb1.com/6a08a02a06a03a04/Candide-by-CliffsNotes.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a05a02a04/Candide-by-Michael-York.pdf