Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d898dd9ebe4f82d…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 18:57:10 +01:00 Authoring application: mPDF 5.7
MD5: 69c4f27f55cd66dc51353beab7b432c9 SHA-1: 094ee05dee0919e9c90a14930ebe2d45bf683c83 SHA-256: 0d898dd9ebe4f82d5cf4212b7ea20d61e5cc0b6322d337a1fd4027e2454c1a7e
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded external links, masquerading as a download farm. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, suggesting a potential distribution mechanism for malicious content. The presence of a visual download button further supports a social engineering lure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a06a08a05a03a05/Ashes-Pechschwarzer-Mond-Ashes-3-part-2-of-2-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/8a09a01a00a03a00/Ashes-Ruhelose-Seelen-Ashes-3-part-1-of-2-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/3a00a06a03a04a03/Ashes-Ashes-Trilogy-1-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/3a05a01a01a01/Ashes-Ashes-Trilogy-1-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/7a04a03a02a07/Shadows-Ashes-Trilogy-2-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/1a00a06a01a08a04a09/Soldier-s-Heart-Part-Two-by-Ilsa-J-Bick.pdf
    • http://muicuiu.dumb1.com/1a01a02a08a09a04a05/Rising-Ashes-Ashes-to-Ashes-3-by-Annie-Anderson.pdf
    • http://muicuiu.dumb1.com/1a01a02a08a09a04a01/Falling-Ashes-Ashes-to-Ashes-2-by-Annie-Anderson.pdf
    • http://muicuiu.dumb1.com/7a06a02a08a08a05/Ashes-to-Ashes-The-Chronicles-of-Hugh-de-Singleton-Surgeon-8-by-Melvin-R-Starr.pdf
    • http://muicuiu.dumb1.com/2a00a00a09a08a06/Dead-Girl-s-Ashes-Dying-Ashes-1-by-Annathesa-Nikola-Darksbane.pdf
    • http://muicuiu.dumb1.com/8a05a01a07a02/Ashes-to-Ashes-Kovac-and-Liska-1-by-Tami-Hoag.pdf
    • http://muicuiu.dumb1.com/2a00a05a05a06a09/Ashes-to-Ashes-Blood-Ties-3-by-Jennifer-Armintrout.pdf
    • http://muicuiu.dumb1.com/2a05a01a09a08a01/Ashes-to-Ashes-Screenplay-by-Wayne-Gerard-Trotman.pdf
    • http://muicuiu.dumb1.com/5a07a04a01a06a00/Ashes-to-Ashes-The-Pyre-of-Karma-by-Haimes-Hensley.pdf
    • http://muicuiu.dumb1.com/3a01a02a00a09a04/Ashes-to-Ashes-The-Chloe-Files-1-by-Howard-Hopkins.pdf
    • http://muicuiu.dumb1.com/1a04a07a08a00a08/Ashes-to-Ashes-Experiment-in-Terror-8-by-Karina-Halle.pdf
    • http://muicuiu.dumb1.com/2a01a07a05a09/Ashes-to-Ashes-America-s-Hundred-Year-Cigarette-War-the-Public-Health-and-the-Unabashed-Triumph-of-Philip-Morris-by-Richard-Kluger.pdf
    • http://muicuiu.dumb1.com/2a01a04a04a00a00/Pocketful-of-Posies-Ashes-Ashes-2-by-Jo-Treggiari.pdf
    • http://muicuiu.dumb1.com/5a09a07a07a04/Ashes-and-Ice-Ashes-and-Ice-1-by-Rochelle-Maya-Callen.pdf
    • http://muicuiu.dumb1.com/3a05a01a05a07a09/Out-of-the-Ashes-The-Ashes-1-by-Diana-Gardin.pdf