Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e8c210a26123c67…

MALICIOUS

PDF

29.1 KB Created: 2019-05-02 01:36:09 +01:00 Authoring application: mPDF 5.7
MD5: 6955d468e767bd323808acf4916fced9 SHA-1: fb91ceb6161fd40ecf1170d1c3a57133c3555099 SHA-256: 0e8c210a26123c6786f09048cab5a3faecbf1a79a1736e9ce6087b038b1147b1
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of external links, many of which are structured as a link farm, suggesting an attempt to direct users to malicious content. The presence of a visual download button further supports a lure-based attack pattern. While no scripts were explicitly extracted, the ML classifier and the link farm heuristic strongly indicate malicious intent, likely to deliver a second-stage payload via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a00a04a06a07a07a08/Untersuchung-Der-Laute-in-Den-Kentischen-Urkunden-by-Rudolf-Wolff.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a03a07a04/Rameaus-Neffe---Studien-Und-Untersuchungen-Zur-Einfuhrung-in-Goethes-Ubersetzung-Des-Diderotschen-Dialogs-by-Rudolf-Schlosser.pdf
    • http://muicuiu.dumb1.com/1a00a03a05a03a07a09/Rameaus-Neffe-Studien-Und-Untersuchungen-Zur-Einf-hrung-in-Goethes-bersetzung-Des-Diderotschen-Dialogs-by-Rudolf-Schlosser.pdf
    • http://muicuiu.dumb1.com/9a00a06a03a08a09/Arnold-Zweig-quot-Der-Streit-Um-Den-Sergeanten-Grischa-quot-by-Rudolf-Wolff.pdf
    • http://muicuiu.dumb1.com/1a00a04a06a06a03a01/Das-laute-Geheimnis-by-Pedro-Calder-n-de-la-Barca.pdf
    • http://muicuiu.dumb1.com/3a04a06a08a06a03/The-Wolff-s-The-Wolff-s-1-by-historygeek123.pdf
    • http://muicuiu.dumb1.com/1a00a04a06a08a03a08/Demokratische-VOR-Laute-Schulerinnenwahl-Zum-Bundestag-98-Ein-Test-in-Sachsen-Anhalt-by-Frank-Tillmann.pdf
    • http://muicuiu.dumb1.com/9a08a06a08a01a09/Die-Laute-Des-Wendischen-Sorbischen-Dialekts-Von-Schleife-in-Der-Oberlausitz-Lautbeschreibung-by-Arnulf-Schroeder.pdf
    • http://muicuiu.dumb1.com/8a07a08a01a01a06/Die-Mysteriendramen-Die-Pforte-der-Einweihung-Die-Pr-fung-der-Seele-Nachspiel-zur-Pforte-der-Einweihung---Vollst-ndige-Ausgabe-Ein-Rosenkreuzermysterium-durch-Rudolf-Steiner-by-Rudolf-Steiner.pdf
    • http://muicuiu.dumb1.com/1a00a02a01a01a03a06/Rudolf-Staffel-Searching-For-Light-by-Rudolf-Staffel.pdf
    • http://muicuiu.dumb1.com/8a07a07a08a07a00/Die-Urkunden-Des-Zisterzienserstiftes-Lilienfeld-1111-1892-by-Stift-Lilienfeld.pdf
    • http://muicuiu.dumb1.com/1a00a01a09a06a05a01/The-Stories-Of-Tobias-Wolff-by-Tobias-Wolff.pdf
    • http://muicuiu.dumb1.com/9a07a05a02a09a01/The-Essential-Rudolf-Steiner-by-Rudolf-Steiner.pdf
    • http://muicuiu.dumb1.com/9a08a08a00a08a05/Allgemeine-Die-Geschichte-Der-Vereinigten-Niederlande-Von-Den-ltesten-Bis-Auf-Gegenw-rtige-Zeiten-Vol-8-of-8-Aus-Den-Glaubw-rdigsten-Schriftstellern-Und-Bew-hrten-Urkunden-Verfasset-Aus-Dem-Holl-ndischen-bersetzt-Nebst-Beygef-gten-Landkarte-by-Unknown.pdf
    • http://muicuiu.dumb1.com/1a01a08a07a02a08a07/Untersuchungen-Zur-Historischen-Landeskunde-Zentrallykiens-by-Martin-Zimmermann.pdf
    • http://muicuiu.dumb1.com/1a01a00a00a00a03a09/Untersuchungen-Zum-Sophokleischen-Philoktet-Das-Auslosende-Ereignis-in-Der-Stuckgestaltung-by-Tamara-Visser.pdf
    • http://muicuiu.dumb1.com/8a09a08a06a05a00/Pollenanalytische-Untersuchungen-Zur-Vegetations--Und-Klimageschichte-Des-Val-Camonica-Norditalien-by-Regula-Gehrig.pdf
    • http://muicuiu.dumb1.com/9a02a00a07a03a05/Untersuchungen-Zum-Motiv-Der-Nackten-Frau-In-Der-Altbabylonischen-Zeit-by-Felix-Blocher.pdf
    • http://muicuiu.dumb1.com/8a07a07a00a03a07/Untersuchungen-Zu-Einer-Mikrooekonomischen-Theorie-Der-Gewerkschaften-by-Hans-Dieter-Kleinhuckelskoten.pdf
    • http://muicuiu.dumb1.com/1a00a04a06a08a00a04/Jerry-Cotton---Folge-3108-Laute-und-leise-Schreie-by-Jerry-Cotton.pdf