Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ad0f89ff1478623…

MALICIOUS

PDF

17.7 KB Created: 2019-04-30 04:16:30 +01:00 Authoring application: mPDF 5.7
MD5: 297c6276efd2f28a6003dba2811b80b1 SHA-1: 5ab81adef604a7afe0ca06a240acb30da1c7a832 SHA-256: 5ad0f89ff1478623414848fc869854bf85f6d0ca5b1cf1de13979a542f2b7e87
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common technique for distributing malicious content or leading users to phishing sites. The ML classifier also strongly indicated maliciousness. The presence of a 'download button' heuristic further supports the intent to trick users into clicking links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a09a03a04a00/Song-of-Solomon-by-Kendra-Norman-Bellamy.pdf
    • http://muicuiu.dumb1.com/1a08a08a04a04a02/One-Prayer-Away-by-Kendra-Norman-Bellamy.pdf
    • http://muicuiu.dumb1.com/4a00a05a08a05a05/For-Love-and-Grace-by-Kendra-Norman-Bellamy.pdf
    • http://muicuiu.dumb1.com/6a05a03a04a05a08/The-Talmud-A-Selection-by-Norman-Solomon.pdf
    • http://muicuiu.dumb1.com/1a09a05a09a00a03/American-Mirror-The-Life-and-Art-of-Norman-Rockwell-by-Deborah-Solomon.pdf
    • http://muicuiu.dumb1.com/9a09a01a01a02/My-Song-Of-Songs-Solomon-s-Touch-by-Joanna-Hynes.pdf
    • http://muicuiu.dumb1.com/5a00a08a04a08a05/The-Sun-Has-Burned-My-Skin-A-Modest-Paraphrase-of-Solomon-s-Song-of-Songs-by-Adam-S-Miller.pdf
    • http://muicuiu.dumb1.com/1a01a08a09a04a07a08/Commentary-on-the-Old-Testament---Volume-6-Proverbs-Ecclesiastes-Song-of-solomon-by-Carl-Friedrich-Keil.pdf
    • http://muicuiu.dumb1.com/4a07a02a06a06a00/Intimacy-Ignited-Conversations-Couple-to-Couple-Fire-Up-Your-Sex-Life-with-the-Song-of-Solomon-by-Joseph-Dillow.pdf
    • http://muicuiu.dumb1.com/2a05a04a00a09a09/The-Solomon-Key-The-Solomon-Key-2-by-Shawn-Hopkins.pdf
    • http://muicuiu.dumb1.com/9a09a08a09a08a08/The-Solomon-Key-The-Solomon-Key-2-by-Shawn-Hopkins.pdf
    • http://muicuiu.dumb1.com/5a00a00a00a02a06/Looking-Backward-by-Edward-Bellamy.pdf
    • http://muicuiu.dumb1.com/2a05a08a03a01a03/White-Ginger-by-Susanne-Bellamy.pdf
    • http://muicuiu.dumb1.com/2a09a02a01a01a04/Bellamy-and-the-Brute-by-Alicia-Michaels.pdf
    • http://muicuiu.dumb1.com/1a01a04a03a05a08a06/Ah-Heck-The-Angel-Chronicles-by-Mary-Bellamy.pdf
    • http://muicuiu.dumb1.com/1a05a04a01a09a01/Looking-Backward-2000-1887-by-Edward-Bellamy.pdf
    • http://muicuiu.dumb1.com/8a07a02a09a07a02/Lark-Bellamy-s-Blossoms-2-by-Ginny-Aiken.pdf
    • http://muicuiu.dumb1.com/1a09a06a09a01a00/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://muicuiu.dumb1.com/1a00a03a02a05a03/It-Doesn-t-Take-a-Hero-The-Autobiography-of-General-H-Norman-Schwarzkopf-by-Norman-Schwarzkopf.pdf
    • http://muicuiu.dumb1.com/2a07a02a07a05a03/Remember-Our-Song-A-Billionaire-Romance-Our-Song-3-by-Emma-South.pdf