Malicious PDF — malware analysis report

Static analysis result for SHA-256 08710b5581dff7ac…

MALICIOUS

PDF

17.4 KB Created: 2019-05-07 04:21:58 +01:00 Authoring application: mPDF 5.7
MD5: a3b4e65bdf7e307ac501f552cdcc3bf0 SHA-1: 51ca1b96cd0793c900b16bd232e00c2dfd15e9b4 SHA-256: 08710b5581dff7ac01452d6c7ef2ce7565bf431f5cb1bc63d5a31883de08d6d1
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the ML classifier flagged it as malicious, the specific URLs extracted were classified as benign. The presence of a 'download button' heuristic suggests a lure, but the primary malicious activity appears to be the generation of a link farm, potentially for SEO manipulation or to distribute other malicious content indirectly.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a09a00a05a06a03/A-History-of-the-World-in-10-Chapters-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/5a08a00a02a09a08/Flaubert-s-parrot-and-A-history-of-the-world-in-10-1-2-chapters-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/3a05a04a01a00a02/Before-She-Met-Me-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/7a09a05a06a08a00/O-Sentido-do-Fim-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/8a02a01a06a07a03/Hygiene-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/4a07a00a06a02a02/Talking-It-Over-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/1a04a03a04a06a03/Nothing-To-Be-Frightened-Of-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/1a03a09a08a09a05/Talking-It-Over-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/4a04a02a00a07a05/The-Sense-of-an-Ending-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/3a04a02a06a00a03/Levels-of-Life-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/1a09a03a06a08a03/Levels-of-Life-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/3a03a02a01a03a08/Letters-from-London-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/3a04a09a08a05a03/Cross-Channel-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/1a09a05a07a09a00/Through-the-Window-Seventeen-Essays-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/1a01a02a04a08a06a09/Through-the-Window-Seventeen-Essays-and-a-Short-Story-by-Julian-Barnes.pdf
    • http://muicuiu.dumb1.com/6a02a00a02a05a08/Masterpieces-Chapters-on-the-History-of-an-Idea-by-Walter-Cahn.pdf
    • http://muicuiu.dumb1.com/1a05a04a04a01/-And-I-Worked-at-the-Writer-s-Trade-Chapters-of-Literary-History-1918-1978-by-Malcolm-Cowley.pdf
    • http://muicuiu.dumb1.com/4a01a04a04a02a08/When-Churchill-Slaughtered-Sheep-and-Stalin-Robbed-a-Bank-History-s-Unknown-Chapters-by-Giles-Milton.pdf
    • http://muicuiu.dumb1.com/6a09a06a07a07a08/Gerrards-Cross-A-History-by-Julian-Hunt.pdf
    • http://muicuiu.dumb1.com/1a00a00a04a09a00a04/Interactive-Cengage-Learing-eBook-World-History-Resource-Center-Instant-Access-Code-for-Duiker-Spielvogel-s-The-Essential-World-History-by-William-J-Duiker.pdf