Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bd4d1c08d2518da…

MALICIOUS

PDF

23.8 KB Created: 2019-04-30 04:53:34 +01:00 Authoring application: mPDF 5.7 First seen: 2021-10-12
MD5: 444a0a2a292965673dd24f19f2647880 SHA-1: 15413d528b16aec35fdbfa8796d38d8908e3ecf0 SHA-256: 3bd4d1c08d2518da636367afecffe26e8159b173ae0b2d0c1818c99568a6ca45
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged this PDF as malicious, the specific intent appears to be a link farm designed to redirect users to other PDF documents. The SE_DOWNLOAD_BUTTON heuristic suggests a call-to-action, further supporting the lure of downloading content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a03a02a09a06/Many-Blessings-A-Tapestry-of-Accomplished-African-American-Women-by-Sonnee-Weedn.pdf In PDF document text
    • http://muicuiu.dumb1.com/2a03a03a07a00a05/A-Tapestry-of-Secrets-Appalachian-Blessings-3-by-Sarah-Loudin-Thomas.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a07a02a09a06a07/A-Movement-Without-Marches-African-American-Women-and-the-Politics-of-Poverty-in-Postwar-Philadelphia-by-Lisa-Levenstein.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a00a04a05a01a02/Domestic-Abuse-in-the-Novels-of-African-American-Women-A-Critical-Study-by-Heather-Duerre-Humann.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a00a08a00a00a09/Talk-with-You-Like-a-Woman-African-American-Women-Justice-and-Reform-in-New-York-1890-1935-by-Cheryl-D-Hicks.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a02a09a05a09/Sisters-in-the-Struggle-African-American-Women-in-the-Civil-Rights-Black-Power-Movement-by-Bettye-Collier-Thomas.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a07a06a07a06a04/African-American-Chronology-Chronologies-of-the-American-Mosaic-by-Kwando-Kinshasa.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a08a01a04a09a04/Italian-American-Women-in-Chicagoland-by-Italian-American-Women-39-s-Club.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a03a01a08a04/Writing-Women-s-Lives-An-Anthology-Of-Autobiographical-Narratives-By-Twentieth-Century-American-Women-Writers-by-Susan-Cahill.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a03a07a06a03a09/In-Their-Own-Voices-African-Women-Writers-Talk-by-Adeola-James.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a03a02a08a08a00/Conjure-in-African-American-Society-by-Jeffrey-E-Anderson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a08a09a05a04a00/African-American-Philosophers-17-Conversations-by-George-Yancy.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a05a02a01a05/I-Freed-Myself-African-American-Self-Emancipation-in-the-Civil-War-Era-by-David-Williams.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a05a01a02a09a09/African-American-Psychology-From-Africa-to-America-by-Faye-Z-Belgrave.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a09a06a01/African-American-Writers-and-Classical-Tradition-by-William-W-Cook.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a02a09a09a01a06/African-Women-Writing-Resistance-An-Anthology-of-Contemporary-Voices-by-Jennifer-Browdy-de-Hernandez.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a06a07a02/Black-Thunder-An-Anthology-of-African-American-Drama-by-William-B-Branch.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a00a05a03a07a04/Jackie-Ormes-The-First-African-American-Woman-Cartoonist-by-Nancy-Goldstein.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a05a04a04a04/Freedom-s-Journey-African-American-Voices-of-the-Civil-War-by-Donald-Yacovone.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a01a06a01a05/Now-Is-Your-Time-The-African-American-Struggle-for-Freedom-by-Walter-Dean-Myers.pdfIn PDF document text