Malicious PDF — malware analysis report

Static analysis result for SHA-256 368a7fd95ff5c7d1…

MALICIOUS

PDF

24.8 KB Created: 2019-04-30 03:19:07 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-04
MD5: 9730a81a661528172dafc57b6cec9304 SHA-1: a33661be7f07c34af942a27d232297a7960987c1 SHA-256: 368a7fd95ff5c7d1589727064c9e633085f8a86fc8bfcb514308fad9f27dbb39
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the document body is unreadable, the presence of a 'download button' heuristic and the sheer volume of links indicate a likely attempt to direct users to malicious content. No scripts were extracted, but the structure implies a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a05a02a04a09a01/Why-England-Lose-amp-Other-Curious-Football-Phenomena-Explained-by-Simon-Kuper.pdf In PDF document text
    • http://muicuiu.dumb1.com/8a09a07a09a04a08/Football-against-the-enemy-oder-Wie-ich-lernte-die-Deutschen-zu-lieben-by-Simon-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a06a09a07a09/Soccernomics-Why-England-Loses-Why-Germany-Spain-and-France-Win-and-Why-One-Day-Japan-Iraq-and-the-United-States-Will-Become-Kings-of-the-World-s-Most-Popular-Sport-by-Simon-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a08a08a08a09/Soccernomics-Why-England-Loses-Why-Germany-and-Brazil-Win-and-Why-the-U-S-Japan-Australia-Turkey--and-Even-Iraq--Are-Destined-to-Become-the-Kings-of-the-World-s-Most-Popular-Sport-by-Simon-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a02a09a07a08/The-FC-Nantes-Experiment-One-Man-s-Odyssey-of-French-Football-by-Simon-Rance.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a04a01a05a04/A-Curious-Guide-to-London-by-Simon-Leyland.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a05a07a01a05a09/The-Curious-Incident-of-the-Dog-in-the-Night-Time-by-Simon-Stephens.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a07a01a08a06/Skulls-An-Exploration-of-Alan-Dudley-s-Curious-Collection-by-Simon-Winchester.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a02a01a05a03a07/Lose-A-Princess-Lose-Your-Head-Merchant-Blades-Volume-2-by-Alex-Avrio.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a03a01a03a06/Football-Outsiders-Almanac-2009-The-Essential-Guide-To-The-2009-Nfl-And-College-Football-Seasons-by-Aaron-Schatz.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a03a01a04a08/Football-Outsiders-Almanac-2015-The-Essential-Guide-to-the-2015-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a04a03a01a03a07/Football-Outsiders-Almanac-2010-The-Essential-Guide-to-the-2010-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a07a01a03/Ruins-by-Peter-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a07a04a01a05/Simon-s-Cat-in-Kitten-Chaos-Simon-s-Cat-3-by-Simon-Tofield.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a06a01a04a06/Anomaly-Schrodinger-s-Consortium-1-by-Tonya-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a09a07a02a06a09/England-Glorious-England-Ann-herung-An-Eigenwillige-Verwandte-by-Holger-Ehling.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a08a06a05a08/Weird-England-Your-Travel-Guide-to-England-s-Local-Legends-and-Best-Kept-Secrets-by-Matt-Lake.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a08a06a03a00a08/Agrippa-Von-Nettesheim-Ein-Echter-Faust-by-Michael-Kuper.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a09a08a05a00a00/Hymns-to-Phenomena-by-S-D-Johnson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a07a03a09a09a00/Diario-de-Oaxaca-A-Sketchbook-Journal-of-Two-Years-in-Mexico-by-Peter-Kuper.pdfIn PDF document text