Malicious PDF — malware analysis report

Static analysis result for SHA-256 164f057516c25994…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 04:21:13 +01:00 Authoring application: mPDF 5.7
MD5: a4039ebaad8a87689e4597d711ec6fe8 SHA-1: 9e87f60f1b1e333fd80b850999d969dd1afa9608 SHA-256: 164f057516c25994b52023bd553c791009e760c8b45d5a508d86d466f6ca1a51
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to manipulate search engine results or direct users to potentially harmful content. The ML classifier also flagged the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a08a05a07a05a03/St-Marien-Dom-in-Hamburg-by-Matthias-Gretzschel.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a05a07a01/Bahnhof-in-Hamburg-Hamburg-Hauptbahnhof-Bahnhof-Hamburg-Altona-Hamburg-Hannoverscher-Bahnhof-Bahnhof-Hamburg-Dammtor-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/8a07a02a06a07a04/Hamburg---hier-lebten-unsere-Promis-II-In-Erinnerung-an-Pers-nlichkeiten-aus-Film-Fernsehen-Politik-Sport-Kultur-by-Matthias-R-he.pdf
    • http://muicuiu.dumb1.com/1a01a01a09a08a03a00/Museum-in-Hamburg-Hamburger-Kunsthalle-Miniatur-Wunderland-Liste-Der-Museen-in-Hamburg-Freilichtmuseum-Am-Kiekeberg-Ballinstadt-by-Quelle-Wikipedia.pdf
    • http://muicuiu.dumb1.com/5a08a05a07a02a09/The-Mari-n-Revelation-by-Miguel-Santana.pdf
    • http://muicuiu.dumb1.com/5a08a05a08a09a08/The-Potential-Of-Educational-Futures-by-Michael-Marien.pdf
    • http://muicuiu.dumb1.com/5a08a05a07a09a07/Neuropsychological-Research-A-Review-by-Peter-Marien.pdf
    • http://muicuiu.dumb1.com/5a08a05a07a02a04/100-Ideas-that-Changed-Photography-by-Mary-Warner-Marien.pdf
    • http://muicuiu.dumb1.com/5a08a05a07a08a06/Hommage-a-Tannewetzel-Neujahrsrede-in-St-Marien-zu-Lubeck-by-Horst-Janssen.pdf
    • http://muicuiu.dumb1.com/5a08a05a07a08a02/Musical-Ekphrasis-in-Rilke-s-Marien-Leben-by-Siglind-Bruhn.pdf
    • http://muicuiu.dumb1.com/5a08a05a08a09a09/Practice-Using-Lotus-1-2-3-Active-Learning-Made-Easy-with-by-Deryk-Marien.pdf
    • http://muicuiu.dumb1.com/1a06a03a01a07a06/Introspection-Transformation-by-Steven-Hamburg.pdf
    • http://muicuiu.dumb1.com/8a01a06a03a05a05/Adalbert-of-Hamburg-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a03a08a00a06a00/ELBSCHARADE---Ein-Hamburg-Krimi-by-Fanny-Duve.pdf
    • http://muicuiu.dumb1.com/6a02a02a07a01a07/Death-in-Hamburg-1974-by-Gay-Toltl-Kinman.pdf
    • http://muicuiu.dumb1.com/9a00a05a04a04a06/Kalt-Erwischt-in-Hamburg-by-Cordula-Schurig.pdf
    • http://muicuiu.dumb1.com/9a05a08a03a05a05/Soziale-Spaltung-in-Hamburg-by-Joachim-Bischoff.pdf
    • http://muicuiu.dumb1.com/3a08a02a07a01a07/Hazy-Bloom-and-the-Tomorrow-Power-by-Jennifer-Hamburg.pdf
    • http://muicuiu.dumb1.com/1a00a00a09a00a00a02/Mach-Schau---Die-Beatles-in-Hamburg-by-Thomas-Rehwagen.pdf
    • http://muicuiu.dumb1.com/1a01a02a02a05a04a09/Stern-Portfolio-69---Nadav-Kander-by-Gruner-Hamburg.pdf