Malicious PDF — malware analysis report

Static analysis result for SHA-256 15b68b41dc7c84be…

MALICIOUS

PDF

30.3 KB Created: 2019-04-30 04:25:49 +01:00 Authoring application: mPDF 5.7
MD5: 0a54da68c4358bf2f89025729e3bdc4c SHA-1: 85b230f1913ab9efc4f9e7f1d8ca2ba8d2285d2c SHA-256: 15b68b41dc7c84be601c7efea29a7aab00988d57717d3e896475328ae9073e30
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, suggesting an attempt to drive traffic to external sites. While the document body is heavily obfuscated, the presence of embedded URLs and a 'SE_DOWNLOAD_BUTTON' heuristic indicates a lure to click these links. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9689

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a04a06a05a01a07/In-the-Kingdom-of-the-Sick-A-Social-History-of-Chronic-Illness-in-America-by-Laurie-Edwards.pdf
    • http://muicuiu.dumb1.com/1a06a08a08a04a08/Life-Disrupted-Getting-Real-about-Chronic-Illness-in-Your-Twenties-and-Thirties-by-Laurie-Edwards.pdf
    • http://muicuiu.dumb1.com/7a02a01a09a09/Defeat-Chronic-Pain-Now-Groundbreaking-Strategies-for-Eliminating-the-Pain-of-Arthritis-Back-and-Neck-Conditions-Migraines-Diabetic-Neuropathy-and-Chronic-Illness-by-Bradley-S-Galer.pdf
    • http://muicuiu.dumb1.com/6a05a01a05a06a03/The-Great-Stagnation-How-America-Ate-All-The-Low-Hanging-Fruit-of-Modern-History-Got-Sick-and-Will-Eventually-Feel-Better-by-Tyler-Cowen.pdf
    • http://muicuiu.dumb1.com/1a01a05a02a06a08a06/LIVING-WITH-CHRONIC-ILLNESS-by-Cheri-Register.pdf
    • http://muicuiu.dumb1.com/4a02a01a08a06a08/In-the-Shadow-of-Death-Reflections-on-a-Chronic-Illness-by-Cyn-Bagley.pdf
    • http://muicuiu.dumb1.com/1a08a08a06a01a06/Sick-amp-Tired-Empathy-Encouragement-and-Practical-Help-for-those-Suffering-from-Chronic-Health-Problems-by-Kimberly-Rae.pdf
    • http://muicuiu.dumb1.com/1a01a09a05a02a02a00/Hope-Beyond-Illness-A-Guide-to-Living-Well-with-a-Chronic-Condition-by-Shulamit-Lando.pdf
    • http://muicuiu.dumb1.com/3a09a03a02a08a06/Dancing-with-Monsters-Chronic-Illness-as-Creative-Transformation-by-Kate-Wolfe-Jenson.pdf
    • http://muicuiu.dumb1.com/9a09a08a05a02a09/Chronically-Happy-Joyful-Living-In-Spite-Of-Chronic-Illness-by-Lori-Hartwell.pdf
    • http://muicuiu.dumb1.com/3a08a05a08a04a04/I-am-Not-Sick-I-Don-t-Need-Help-How-to-Help-Someone-With-Mental-Illness-Accept-Treatment-by-Xavier-Francisco-Amador.pdf
    • http://muicuiu.dumb1.com/2a05a06a09a09a06/The-Architecture-of-America-A-Social-and-Cultural-History-by-John-Burchard.pdf
    • http://muicuiu.dumb1.com/3a08a05a09a02a08/Managing-Chronic-Illness-Using-the-Four-Phase-Treatment-Approach-A-Mental-Health-Professional-s-Guide-to-Helping-Chronically-Ill-People-by-Patricia-A-Fennell.pdf
    • http://muicuiu.dumb1.com/3a04a02a01a09a00/How-America-Eats-A-Social-History-of-U-S-Food-and-Culture-American-Ways-Series-by-Jennifer-Jensen-Wallach.pdf
    • http://muicuiu.dumb1.com/6a09a06a06a08a03/Healthcare-Partnerships-for-Pediatric-Adherence-Promoting-Collaborative-Management-for-Pediatric-Chronic-Illness-Care-by-David-D-Schwartz.pdf
    • http://muicuiu.dumb1.com/2a03a09a01a02a01/Staying-Well-in-a-Toxic-World-Understanding-Environmental-Illness-Multiple-Chemical-Sensitivities-Chemical-Injuries-and-Sick-Building-Syndrome-by-Lynn-Lawson.pdf
    • http://muicuiu.dumb1.com/2a03a08a05a07a09/Abortion-Rites-A-Social-History-of-Abortion-in-America-by-Marvin-Olasky.pdf
    • http://muicuiu.dumb1.com/5a06a00a03a07a06/Works-of-Illness-Narrative-Picturing-and-the-Social-Response-to-Serious-Disease-by-Alan-Radley.pdf
    • http://muicuiu.dumb1.com/3a02a02a07a03a02/Worried-Sick-A-Prescription-for-Health-in-an-Overtreated-America-by-Nortin-M-Hadler.pdf
    • http://muicuiu.dumb1.com/3a04a04a00a04a02/America-s-Biggest-Cover-Up-50-More-Things-Everyone-Should-Know-About-the-Chronic-Fatigue-Syndrome-Epidemic-And-Its-Link-to-AIDS-by-Neenyah-Ostrom.pdf