Malicious PDF — malware analysis report

Static analysis result for SHA-256 18db39cec55ec249…

MALICIOUS

PDF

22.4 KB Created: 2019-04-30 08:43:34 +01:00 Authoring application: mPDF 5.7
MD5: fc41f633861b011d65373562530dc9d3 SHA-1: a85860dc198e79a77205ca5a47503e6eee60142b SHA-256: 18db39cec55ec249d1314690367ac709164f568325d44f3f2c09a7319da9958f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, which is indicative of a link farm designed to trick users into downloading malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. While the document body contains garbled text, the presence of numerous links and the heuristic firings strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a02a01a01a05a06/Friends-Stories-About-New-Friends-Old-Friends-And-Unexpectedly-True-Friends-by-Ann-M-Martin.pdf
    • http://muicuiu.dumb1.com/6a02a00a00a07a01/Jonathan-Cahn-s-Biblical-Teachings-Volume-1-by-Jonathan-Cahn.pdf
    • http://muicuiu.dumb1.com/9a00a09a04a03a07/Vanity-Fair-1848-by-William-Makepeace-Thackeray-Illustrated-Vanity-Fair-Is-an-English-Novel-by-William-Makepeace-Thackeray-Which-Follows-the-Lives-of-Becky-Sharp-and-Emmy-Sedley-Amid-Their-Friends-and-Families-During-and-After-the-Napoleonic-Wars-by-William-Makepeace-Thackeray.pdf
    • http://muicuiu.dumb1.com/3a03a04a04a04a06/Friends-and-Enemies-by-William-Dusty.pdf
    • http://muicuiu.dumb1.com/2a05a04a07a00a00/Friends-of-the-Wigwam-by-John-William-Huelskamp.pdf
    • http://muicuiu.dumb1.com/1a09a01a04a02a07/Brothers-In-Battle-Best-of-Friends-by-William-Guarnere.pdf
    • http://muicuiu.dumb1.com/2a01a02a05a00a07/Friends-and-Enemies-Stellar-Conflict-Book-1-by-William-Dusty.pdf
    • http://muicuiu.dumb1.com/2a05a03a09a02a09/The-History-of-Pendennis-His-Fortunes-and-Misfortunes-His-Friends-and-His-Greatest-Enemy-by-William-Makepeace-Thackeray.pdf
    • http://muicuiu.dumb1.com/3a05a08a06a07a02/The-Geek-Murder-by-William-L-Mansfield.pdf
    • http://muicuiu.dumb1.com/9a02a00a00a03a07/An-Echo-of-Murder-William-Monk-23-by-Anne-Perry.pdf
    • http://muicuiu.dumb1.com/3a08a00a05a09a02/Jessica-Darling-s-It-List-2-The-Totally-Not-Guaranteed-Guide-to-Friends-Foes-amp-Faux-Friends-by-Megan-McCafferty.pdf
    • http://muicuiu.dumb1.com/2a07a00a05a02a03/Friends-Don-t-Let-Friends-be-Undead-by-Seth-Tucker.pdf
    • http://muicuiu.dumb1.com/1a04a07a00a03a04/Let-s-Be-Just-Friends-Just-Friends-1-by-Camilla-Isley.pdf
    • http://muicuiu.dumb1.com/3a05a06a05a05a02/Friends-Like-These-Friends-Like-These-1-by-Hannah-Ellis.pdf
    • http://muicuiu.dumb1.com/4a02a08a07a04/I-Don-t-Want-To-Be-Friends-Just-Friends-4-by-Camilla-Isley.pdf
    • http://muicuiu.dumb1.com/6a03a03a03a02/Let-s-Be-Just-Friends-Just-Friends-1-by-Camilla-Isley.pdf
    • http://muicuiu.dumb1.com/6a02a00a02a00a01/Red-Spike-Volume-1-by-Jeff-Cahn.pdf
    • http://muicuiu.dumb1.com/6a02a00a00a07a04/The-Harbinger-Decoded-by-Jonathan-Cahn.pdf
    • http://muicuiu.dumb1.com/6a02a00a01a05a01/Managing-Conflict-Through-Communication-by-Dudley-D-Cahn.pdf
    • http://muicuiu.dumb1.com/6a02a00a00a06a08/I-Dare-Me-How-I-Rebooted-and-Recharged-My-Life-by-Doing-Something-New-Every-Day-by-Lu-Ann-Cahn.pdf