Malicious PDF — malware analysis report

Static analysis result for SHA-256 0cef5b845558b6b3…

MALICIOUS

PDF

15.8 KB Created: 2019-05-03 06:32:36 +01:00 Authoring application: mPDF 5.7
MD5: e2ec86eefe98d981f18d968e247ec9fc SHA-1: af3d221b092263ff37769875560d62c1aa53ed88 SHA-256: 0cef5b845558b6b3f028690d671a6e246bfa740f5cf20d619861634532bc93be
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified as a "PDF_SEO_LINK_FARM" heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to manipulate search engine results or direct users to a large collection of content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a01a05a04a08a09/Crystal-The-Snow-Fairy-Rainbow-Magic-8-Weather-Fairies-1-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/7a06a01a08a08/Danielle-the-Daisy-Fairy-Rainbow-Magic-48-Petal-Fairies-6-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a09a01a02a02a06/Mia-the-Bridesmaid-Fairy-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a09a01a00a03a05/Juliet-The-Valentine-Fairy-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/1a09a09a07a09a09/Ruby-the-Red-Fairy-Rainbow-Magic-1-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/1a00a01a07a08a08a09/Shannon-the-Ocean-Fairy-Special-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/2a09a00a01a00a07/Natalie-the-Christmas-Stocking-Fairy-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/3a01a02a04a07a03/Amber-The-Orange-Fairy-Rainbow-Magic-2-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/6a05a02a04a00/Stacey-The-Soccer-Fairy-Sports-Fairies-2-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/5a02a08a05a02/Gemma-the-Gymnastic-Fairy-Sporty-Fairies-7-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/3a01a02a02a09a02/Tia-the-Tulip-Fairy-Rainbow-Magic-43-Petal-Fairies-1-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/7a08a03a05a03/Louise-the-Lily-Fairy-Rainbow-Magic-Petal-Fairies-3-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a05a01a07a04a07/Melodie-the-Music-Fairy-Rainbow-Magic-16-Party-Fairies-2-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/7a00a08a02a01/Jessica-The-Jazz-Fairy-Rainbow-Magic-The-Dance-Fairies-5-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a08a02a07a05a00/India-The-Moonstone-Fairy-Rainbow-Magic-22-Jewel-Fairies-1-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/6a06a09a01a04/Helena-the-Horseriding-Fairy-Rainbow-Magic-Sporty-Fairies-1-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/7a07a07a02a00/Charlotte-The-Sunflower-Fairy-Rainbow-Magic-Petal-Fairies-4-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/7a05a04a03a09/Ella-The-Rose-Fairy-Rainbow-Magic-Petal-Fairies-7-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a09a01a00a03a02/Fiona-the-Flute-Fairy-Rainbow-Magic-Music-Fairies-3-by-Daisy-Meadows.pdf
    • http://muicuiu.dumb1.com/4a09a00a08a02a09/Maya-the-Harp-Fairy-Rainbow-Magic-Music-Fairies-5-by-Daisy-Meadows.pdf