Malicious PDF — malware analysis report

Static analysis result for SHA-256 445b527490eb7891…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 04:29:24 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-13
MD5: 060d9c81d1f644ab1a1ca61adffd8b48 SHA-1: db0c4cbed4daebeb005905790e28f4a610fb96a5 SHA-256: 445b527490eb7891d6cb4664256e04bf7a810a999eb5fa5dceedf94d204605f6
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of external links, many of which are structured as book titles, suggesting a link farm designed to attract traffic or distribute malicious content. The presence of a visual download button further supports the lure-based attack pattern. While no scripts were explicitly extracted, the PDF structure and link farm heuristic indicate a potential for malicious redirection or download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9806

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a05a03a01a01a04/The-Deja-Vu-Experiment-by-J-G-Renato.pdf In PDF document text
    • http://muicuiu.dumb1.com/8a05a02a09a06a00/Nikki-and-Deja-Birthday-Blues-Nikki-and-Deja-Book-Two-by-Karen-English.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a02a09a06a08/Nikki-and-Deja-Wedding-Drama-Nikki-and-Deja-Book-Five-by-Karen-English.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a01a02a03a00a02/Intercept-UFO-by-Renato-Vesco.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a07a02a07a04a00/Der-achte-Beauftragte-Roman-editionBalkan-14-by-Renato-Bareti-.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a09a08a00a03/Evolution-The-Grand-Experiment-2nd-Edition-Evolution-The-Grand-Experiment-Book-Series-by-Carl-Werner.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a05a03a05a05a05/Culture-amp-Truth-The-Remaking-of-Social-Analysis-by-Renato-Rosaldo.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a05a08a06a04a04/Il-Museo-Renato-Marino-Mazzacurati-Opere-Dalla-Donazione-Carla-Marzi-by-Martina-De-Luca.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a00a05a00a04a07/Deja-Vu-Sisterhood-19-by-Fern-Michaels.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a02a08a07a01/Murder-Deja-Vu-by-Polly-Iyer.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a02a09a07a00/Deja-Voodoo-by-Leslie-Brown.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a04a00a07a05/Deja-Brew-by-Taneka-Stotts.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a08a07a06a04a08/Deja-New-Insighter-2-by-MaryJanice-Davidson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a03a06a02a02/Deja-Vu-Bride-by-Debra-Ullrick.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a00a09a09a00a04/Deja-Who-Insighter-1-by-MaryJanice-Davidson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a02a09a07a08/Then-There-Was-X-Deja-Series-by-Tajana-Sutton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a01a05a02a07a08/Deja-Vu-Titan-7-5-by-Cristin-Harber.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a03a01a03a08a01/The-Explainer-From-Deja-Vu-To-Why-The-Sky-Is-Blue-And-Other-Conundrums-by-The-Conversation.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a03a00a07a00/Rich-Or-Famous-Part-2-by-Deja-King.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a06a01a02a00/D-j-Dead-Temperance-Brennan-1-by-Kathy-Reichs.pdfIn PDF document text