Malicious PDF — malware analysis report

Static analysis result for SHA-256 08adc68e5c009a1e…

MALICIOUS

PDF

13.8 KB Created: 2019-05-08 18:43:32 +01:00 Authoring application: mPDF 5.7
MD5: 7a46d2133074bf65dba777f5dcaa4137 SHA-1: 86ce6515ce0f419e6a693b1e4922e587aed67808 SHA-256: 08adc68e5c009a1e9180cb85d6c516bccaec318bbb346e0c4dc43ea1bffa9f94
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, which are likely intended to trick users into downloading malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. While no scripts were extracted, the structure and heuristics suggest a phishing or social engineering attack, likely initiated via spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a02a01a09a05/Beloved-Impostor-Beloved-Trilogy-1-by-Patricia-Potter.pdf
    • http://muicuiu.dumb1.com/1a01a09a07a01/Beloved-Warrior-Beloved-Trilogy-3-by-Patricia-Potter.pdf
    • http://muicuiu.dumb1.com/1a02a04a05a01a06/Beloved-Luna-Beloved-1-by-Kanika-Bankhad.pdf
    • http://muicuiu.dumb1.com/3a01a03a00a06a08/Discovering-Isaac-The-Beloved-Potter-of-Niederbipp-Remembering-Isaac-2-by-Ben-Behunin.pdf
    • http://muicuiu.dumb1.com/3a00a06a09a09a00/The-Sheikh-s-Beloved-Sheikh-s-Beloved-1-2-by-Katheryn-Lane.pdf
    • http://muicuiu.dumb1.com/2a01a03a08a00a08/The-Beloved-by-P-A-Minyard.pdf
    • http://muicuiu.dumb1.com/2a05a01a04a00a02/My-Beloved-The-Witch-by-T-M-Mendes.pdf
    • http://muicuiu.dumb1.com/2a01a04a07a07a03/Come-Away-My-Beloved-by-Frances-J-Roberts.pdf
    • http://muicuiu.dumb1.com/2a00a04a04a09a01/Beloved-Idea-by-Ann-Killough.pdf
    • http://muicuiu.dumb1.com/9a05a06a06a00a01/The-Beloved-by-David-Helwig.pdf
    • http://muicuiu.dumb1.com/2a05a00a04a09a00/Once-Beloved-by-Amara-Royce.pdf
    • http://muicuiu.dumb1.com/3a05a08a04a05a07/Beloved-by-Toni-Morrison.pdf
    • http://muicuiu.dumb1.com/2a03a05a09a05a02/Such-Is-My-Beloved-by-Morley-Callaghan.pdf
    • http://muicuiu.dumb1.com/4a07a09a06a09a07/The-Well-Beloved-by-Thomas-Hardy.pdf
    • http://muicuiu.dumb1.com/9a01a04a07a00/Beloved-Stranger-by-Meg-Hudson.pdf
    • http://muicuiu.dumb1.com/4a04a03a03a06a06/The-Well-Beloved-by-Thomas-Hardy.pdf
    • http://muicuiu.dumb1.com/4a00a05a05a04a06/Beloved-Dog-by-Maira-Kalman.pdf
    • http://muicuiu.dumb1.com/1a05a07a03a00a01/The-Beloved-by-Annah-Faulkner.pdf
    • http://muicuiu.dumb1.com/5a01a00a04a02/Beloved-Friend-by-Nancy-P-Gilsenan.pdf
    • http://muicuiu.dumb1.com/6a07a09a09a05a05/Beloved-Infidel-by-Sheilah-Graham.pdf