Malicious PDF — malware analysis report

Static analysis result for SHA-256 13ba0be2105cae38…

MALICIOUS

PDF

19.0 KB Created: 2019-05-05 16:51:38 +01:00 Authoring application: mPDF 5.7
MD5: 952d8c8988ad6fc650ab482df6975022 SHA-1: 0aed73bf4ec6daf2405093ed670a864a66e8cad0 SHA-256: 13ba0be2105cae38b990b95b7cde8dee72828bce7ff42c7d1bd1798456ac6767
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a mass of external links disguised as book titles, a technique often used for SEO poisoning or to lure users to malicious sites. The ML classifier strongly flagged this PDF as malicious, and the presence of a visual download button further supports a deceptive intent. The primary goal appears to be directing users to download other PDFs from the `muicuiu.dumb1.com` domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a05a06a04a08a05/Midsummer-Nights-Dream-3D-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a04a01a00a02a03/A-Midsummer-Night-s-Dream-By-William-Shakespeare---Illustrated-Comes-with-a-Free-Audiobook-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a08a02a00a02a06/A-Midsummer-Nights-Dream-With-Side-By-Side-Modern-English-Translation-Shakespeare-Side-By-Side-Translation-Book-14-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a03a08a07a00a05/A-New-Variorum-Edition-of-Shakespeare-Midsummer-Night-s-Dream-1895-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a04a07a00a01a00/Shakespeare-s-Comedy-of-a-Midsummer-Night-s-Dream-with-Notes-by-S-Neil-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/8a04a01a07a02a04/A-Midsummer-Night-s-Dream-with-related-Readings-Global-Shakespeare-Series-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a03a02a05a02a08/A-Midsummer-Night-s-Dream-Propeller-Shakespeare-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/8a06a03a03a09a07/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/8a08a08a08a06a06/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a04a09a09a08a09/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/3a06a07a00a03a01/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a08a03a05a01a01/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/3a03a04a00a09a09/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a06a03a06a03a00/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a07a09a04a09a01/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a03a01a05a03a05/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/8a06a03a06a08a02/A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/7a06a07a02a06a02/An-Introduction-To-A-Midsummer-Night-s-Dream-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/6a02a04a01a09a07/Midsummer-Night-s-Dream-amp-Writing-About-Literature-by-William-Shakespeare.pdf
    • http://muicuiu.dumb1.com/5a02a06a07a06a01/Le-Songe-d-une-nuit-d-t---A-midsummer-night-s-dream-by-William-Shakespeare.pdf