Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ba48c7b7fff5343…

MALICIOUS

PDF

25.1 KB Created: 2019-04-30 03:39:58 +01:00 Authoring application: mPDF 5.7
MD5: ce842d76134efda03e94f2f846c60356 SHA-1: 1aeb9550a074185c5a215ba056917913d1886135 SHA-256: 0ba48c7b7fff534379be786fd1069cd68d77728e21e0f7d228975b8701e7d19b
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs disguised as book titles, forming a link farm. While the document body is heavily obfuscated, the presence of a 'PDF_SEO_LINK_FARM' heuristic and numerous external links strongly suggests a malicious intent to redirect users to potentially harmful sites. No scripts were extracted, but the structure indicates a lure for initial access, likely via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a06a00a08a06a09/The-Generalissimo-Chiang-Kai-Shek-and-the-Struggle-for-Modern-China-by-Jay-Taylor.pdf
    • http://muicuiu.dumb1.com/1a04a03a08a02a02/Chiang-Kai-Shek-China-s-Generalissimo-and-the-Nation-He-Lost-by-Jonathan-Fenby.pdf
    • http://muicuiu.dumb1.com/9a05a04a01a04a05/Where-Chiang-Kai-Shek-Lost-China-The-Liao-Shen-Campaign-1948-by-Harold-M-Tanner.pdf
    • http://muicuiu.dumb1.com/1a00a02a09a03a03/Rivals-How-the-Power-Struggle-Between-China-India-and-Japan-Will-Shape-Our-Next-Decade-by-Bill-Emmott.pdf
    • http://muicuiu.dumb1.com/5a06a00a01a03a03/Modern-Afghanistan-A-History-of-Struggle-and-Survival-by-Amin-Saikal.pdf
    • http://muicuiu.dumb1.com/3a01a07a00a01a01/A-Coward-in-Modern-China-by-Jon-Lee-Junior.pdf
    • http://muicuiu.dumb1.com/1a06a00a08a08a00/The-Search-For-Modern-China-by-Jonathan-D-Spence.pdf
    • http://muicuiu.dumb1.com/1a01a07a02a05a04a01/Modern-China-and-Opium-A-Reader-by-Alan-Thomas-Baumler.pdf
    • http://muicuiu.dumb1.com/1a09a06a04a08a06/Wild-Grass-Three-Stories-of-Change-in-Modern-China-by-Ian-Johnson.pdf
    • http://muicuiu.dumb1.com/1a09a06a06a09a07/The-Exact-Unknown-and-Other-Tales-of-Modern-China-by-Isham-Cook.pdf
    • http://muicuiu.dumb1.com/1a03a02a08a03a06/The-Opium-War-Drugs-Dreams-and-the-Making-of-Modern-China-by-Julia-Lovell.pdf
    • http://muicuiu.dumb1.com/8a08a02a00a08/Empress-Dowager-Cixi-The-Concubine-Who-Launched-Modern-China-by-Jung-Chang.pdf
    • http://muicuiu.dumb1.com/4a00a03a02a06a03/Mongol-Empire-The-Conquests-of-Genghis-Khan-and-the-Making-of-Modern-China-by-John-Man.pdf
    • http://muicuiu.dumb1.com/5a05a09a06a08a01/Fragmentation-and-Dramatic-Moments-Zhang-Tianyi-and-the-Narrative-Discourse-of-Upheaval-in-Modern-China-by-Yifeng-Sun.pdf
    • http://muicuiu.dumb1.com/1a00a05a03a02a09a07/The-Penguin-History-of-Modern-China-The-Fall-and-Rise-of-a-Great-Power-1850-2008-by-Jonathan-Fenby.pdf
    • http://muicuiu.dumb1.com/6a09a03a04a06a04/French-Canadian-amp-Quebecois-Novels-by-Ben-Z-Shek.pdf
    • http://muicuiu.dumb1.com/1a00a06a02a00a07a05/Mein-Kampf---My-Struggle-Unabridged-edition-of-Hitlers-original-book---Four-and-a-Half-Years-of-Struggle-against-Lies-Stupidity-and-Cowardice-by-Adolf-Hitler.pdf
    • http://muicuiu.dumb1.com/1a00a09a05a02a04a08/Revolutionary-Full-Bible-Theology-from-Israel-China-s-Sole-Path-to-Superpower-Preeminence-Overturning-Judeo-Christianity-Is-the-Reason-for-Modern-Israel-s-Existence-by-Mendel-Edwardson.pdf
    • http://muicuiu.dumb1.com/5a08a05a02a05a08/Revolution-in-the-Revolution-Armed-Struggle-and-Political-Struggle-in-Latin-America-by-R-gis-Debray.pdf
    • http://muicuiu.dumb1.com/2a04a05a01a02/Hell-is-the-Absence-of-God-by-Ted-Chiang.pdf