Malicious PDF — malware analysis report

Static analysis result for SHA-256 3dbf93b1069dbf53…

MALICIOUS

PDF

14.4 KB Created: 2019-04-30 04:24:59 +01:00 Authoring application: mPDF 5.7 First seen: 2021-10-11
MD5: 1e0e2232acd1c2a95d4f0027f601dce5 SHA-1: 63a87b352a218c3195ac29eea5db544d15ebe134 SHA-256: 3dbf93b1069dbf5309b6366b3deb54b6b278f9a054a5956c5341884c81825a6d
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm of 20 external PDF files, suggesting a tactic to distribute or redirect users to other malicious content. The ML classifier also flagged this PDF as malicious. The embedded URLs are presented as book titles, likely a lure to encourage clicks. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a00a06a02a07a03/Amanda-s-Texas-Rangers-by-Leah-Brooke.pdf In PDF document text
    • http://muicuiu.dumb1.com/2a09a03a05a06/The-Way-of-the-Coyote-Texas-Rangers-3-by-Elmer-Kelton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a02a03a05a04a01/Alphas-Mate-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a02a02a01a01/Alphas-Mate-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a05a00a02a04/Saving-Hope-Men-of-the-Texas-Rangers-1-by-Margaret-Daley.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a00a02a04a03/Scorned-Justice-Men-of-the-Texas-Rangers-3-by-Margaret-Daley.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a07a07a01a05/Untamed-Desire-Founding-Fathers-1-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a02a08a04a08a07/Scandalous-Desire-Founding-Fathers-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a00a09a07a00a04/Scandalous-Desire-Founding-Fathers-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a00a03a03a07/The-Legend-Begins-The-Texas-Rangers-1823-1845-by-Frederick-Wilkins.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a07a07a02a04/Desire-for-Three-Winning-Back-Jesse-More-Desire-Oklahoma-1-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a05a09a05a07/Dakota-Ranch-Crude-Dakota-Heat-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a06a03a00a00a08/Panthers-Pride-Black-Panthers-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a01a01a05a09a05/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a08a06a01a09a09/Submission-to-Desire-Desire-Oklahoma-7-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a02a04a07a05/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a01a07a02a02/Rules-Of-Desire-Desire-Oklahoma-4-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a01a04a02a05/Desire-for-Three-Desire-Oklahoma-1-by-Leah-Brooke.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a01a06a05a09a03/At-Bluebonnet-Lake-Texas-Crossroads-1-by-Amanda-Cabot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a09a02a09a01/Reliques-of-Irish-Poetry-1789-A-Memoir-Of-Miss-Brooke-1816-by-Charlotte-Brooke.pdfIn PDF document text