Malicious PDF — malware analysis report

Static analysis result for SHA-256 07d285adfd4f0d59…

MALICIOUS

PDF

17.8 KB Created: 2019-05-06 16:39:54 +01:00 Authoring application: mPDF 5.7
MD5: 0b943c3a704e07ec35ae626c27785686 SHA-1: ce257222f02b24ff86b5c6d752b48d90b961cf72 SHA-256: 07d285adfd4f0d5996d75b4b3175f7ecd0c594f30975e5200bbd29b0b2e909ee
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm, which is a common tactic for distributing malicious content. The ML classifier also flagged this PDF as malicious with high confidence. The presence of a 'download' button heuristic further supports the malicious intent of luring users to download files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a08a01a04a07a02/Eifersucht-hat-rote-Haare-Band-2-by-Anne-Marie-K-fer.pdf
    • http://muicuiu.dumb1.com/1a01a04a01a00a01a06/Das-rote-Band-der-Liebe-Band-2-In-der-Mitte-der-Liebe-ist-es-schwerelos-by-Diana-Mandel.pdf
    • http://muicuiu.dumb1.com/9a08a01a04a07a09/Eifersucht-Eifersucht-berwinden-und-gl-ckliche-Liebesbeziehungen-f-hren-Vertrauen-Zuverl-ssigkeit-und-gegenseitige-Achtung---so-f-hren-Sie-eine-erf-llende-Beziehung-by-Karina-Loffbrandt.pdf
    • http://muicuiu.dumb1.com/1a01a08a01a05a03a08/Gutenachtgeschichten-Band-2-by-Marie-Luise-Messer.pdf
    • http://muicuiu.dumb1.com/9a09a01a05a00a06/Perry-Rhodan-9-Das-rote-Universum-Silberband-3-Band-des-Zyklus-quot-Altan-und-Arkon-quot-Perry-Rhodan-Silberband-German-Edition-by-Clark-Darlton.pdf
    • http://muicuiu.dumb1.com/3a09a06a05a05a00/The-Orphan-Band-of-Springdale-by-Anne-Nesbet.pdf
    • http://muicuiu.dumb1.com/3a09a09a04a00a08/The-Amazigh-s-Apprentice-by-Ri-J-Haare.pdf
    • http://muicuiu.dumb1.com/9a08a02a07a08a06/Du-hast-ja-Haare-auf-der-Brust-by-Norma-Banzi.pdf
    • http://muicuiu.dumb1.com/6a08a08a07a00a08/Hey-Charleston-The-True-Story-of-the-Jenkins-Orphanage-Band-by-Anne-Rockwell.pdf
    • http://muicuiu.dumb1.com/2a02a03a08a03a07/The-Quiet-by-Anne-Marie-Turza.pdf
    • http://muicuiu.dumb1.com/3a01a05a00a03a07/Collision-Course-by-Anne-Marie-Flemming.pdf
    • http://muicuiu.dumb1.com/4a03a01a06a06a05/The-Anne-Marie-by-Israel-J-Parker.pdf
    • http://muicuiu.dumb1.com/5a00a09a06a01a07/Cet-t-on-d-m-nage-by-Anne-Marie-Desplat-Duc.pdf
    • http://muicuiu.dumb1.com/2a02a02a03a05a06/Torrents-by-Marie-Anne-Desmarest.pdf
    • http://muicuiu.dumb1.com/3a08a03a03a02a01/Holiday-Confessions-by-Anne-Marie-Winston.pdf
    • http://muicuiu.dumb1.com/6a08a00a05a00a04/Urban-Dynamics-by-Anne-Marie-Autissier.pdf
    • http://muicuiu.dumb1.com/3a09a06a03a02a08/Fleet-Hospital-by-Anne-Marie-Duquette.pdf
    • http://muicuiu.dumb1.com/3a05a09a06a06a03/Love-Reign-o-er-Me-Behind-Blue-Eyes-1-by-Anne-Marie-Klein.pdf
    • http://muicuiu.dumb1.com/7a01a08a07a06a07/Gratien-Gelinas-La-Ferveur-Et-Le-Doute-by-Anne-Marie-Sicotte.pdf
    • http://muicuiu.dumb1.com/1a09a01a00a08a01/Unearthing-Gotham-The-Archaeology-of-New-York-City-by-Anne-Marie-Cantwell.pdf