Malicious PDF — malware analysis report

Static analysis result for SHA-256 0878868ebd4b16f0…

MALICIOUS

PDF

17.7 KB Created: 2019-05-02 01:32:27 +01:00 Authoring application: mPDF 5.7
MD5: c133bc32b6fd8c607b294216b99ed6ec SHA-1: 94c468f2baa9ef09745358a5e63bd0c83065f73a SHA-256: 0878868ebd4b16f07c86520039f888ae74de41044a48f95bd64672f45fdf8c75
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to manipulate search engine results or direct users to a large collection of external content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a03a07a07a06a08/Road-Trip-Around-Australia-BiteSize-Travel-4-by-Christina-Neubauer.pdf
    • http://muicuiu.dumb1.com/4a03a07a04a01a05/Historic-Treasures-of-Uzbekistan-Journey-of-Discovery-Along-the-Silk-Road-BiteSize-Travel-7-by-Peter-Clarke.pdf
    • http://muicuiu.dumb1.com/2a08a06a09a05/Once-Upon-a-Road-Trip-Once-Upon-a-Road-Trip-1-by-Angela-N-Blount.pdf
    • http://muicuiu.dumb1.com/4a03a08a01a03a07/Quite-Literally-Barcelona-BiteSize-Travel-5-by-Gill-Balfour.pdf
    • http://muicuiu.dumb1.com/4a00a07a00a05/In-Search-of-Captain-Zero-A-Surfer-s-Road-Trip-Beyond-the-End-of-the-Road-by-Allan-C-Weisbecker.pdf
    • http://muicuiu.dumb1.com/1a01a06a01a04a09a04/Kakadu-National-Park-Australia-A-Concise-Travel-Guide-by-Jason-Hale.pdf
    • http://muicuiu.dumb1.com/4a02a01a06a08a06/Road-Trip-by-Barbara-Ann-Derksen.pdf
    • http://muicuiu.dumb1.com/5a09a06a06a02a06/Road-Trip-by-Ru-Dela-Torre.pdf
    • http://muicuiu.dumb1.com/3a00a00a05a02a03/Road-Trip-by-Dylan-Cross.pdf
    • http://muicuiu.dumb1.com/2a05a03a04a00a01/Road-Trip-by-Lucy-Felthouse.pdf
    • http://muicuiu.dumb1.com/1a01a00a03a04a09/Once-Upon-an-Ever-After-Once-Upon-a-Road-Trip-2-by-Angela-N-Blount.pdf
    • http://muicuiu.dumb1.com/5a08a09a01a09/Road-Trip-by-Gary-Paulsen.pdf
    • http://muicuiu.dumb1.com/6a04a08a07a06/Road-Trip-to-Love-by-Nylla-Camphry.pdf
    • http://muicuiu.dumb1.com/3a05a01a05a01a02/Detour-My-Bipolar-Road-Trip-in-4-D-by-Lizzie-Simon.pdf
    • http://muicuiu.dumb1.com/4a06a00a04a03a05/Japanese-Baseball-Road-Trip-Guide-by-Jim-Spavins.pdf
    • http://muicuiu.dumb1.com/2a08a00a00a00a05/The-Damned-Balkans-A-Refugee-Road-Trip-by-John-Farebrother.pdf
    • http://muicuiu.dumb1.com/2a03a08a09a07a04/Diners-Drive-ins-and-Dives-An-All-American-Road-Trip-by-Guy-Fieri.pdf
    • http://muicuiu.dumb1.com/1a01a08a09a04a06a08/Road-Trip-Diary-of-a-Teenage-Girl-Chloe-3-by-Melody-Carlson.pdf
    • http://muicuiu.dumb1.com/4a01a02a04a07a00/Sister-Slam-and-the-Poetic-Motormouth-Road-Trip-by-Linda-Oatman-High.pdf
    • http://muicuiu.dumb1.com/3a04a03a07a03a03/Ilf-and-Petrov-s-American-Road-Trip-The-1935-Travelogue-of-Two-Soviet-Writers-by-Ilya-Ilf.pdf