Malicious PDF — malware analysis report

Static analysis result for SHA-256 5bd0f4295ee1d1b3…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 07:56:43 +01:00 Authoring application: mPDF 5.7
MD5: d644b9b40ce1813082d907da21f5b5fd SHA-1: 5c73963dafc2659e220e96b4a47311c033d82507 SHA-256: 5bd0f4295ee1d1b30d74c372c77c75472ceac96a6f2ac7ad6d2e7136405c8cc4
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to external PDF files, suggesting a link farm for SEO or malicious redirection. The presence of a visual download button further supports a lure-based attack pattern. While no scripts were explicitly extracted, the PDF structure and embedded URLs indicate a potential for malicious content delivery, likely through spearphishing attachments.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a02a09a04a09a01/Hare-Krishna-Hare-Krishna-Five-Distinguished-Scholars-on-the-Krishna-Movement-in-the-West-Harvey-Cox-Larry-D-Shinn-Thomas-J-Hopkins-A-L-Basham-Shrivatsa-Goswami-by-Steven-J-Gelberg.pdf
    • http://muicuiu.dumb1.com/7a04a08a03a04a09/The-Bhagavad-Gita-Or-a-Discourse-Between-Krishna-and-Arjuna-on-Divine-Matters-by-Krishna-Dwaipayana-Vyasa.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a01a05a07/The-Complete-Silver-Strand-Series-5-Full-Length-Novels-1-Novella-Boxed-Set-Silver-Strand-1-5-by-Steph-Campbell.pdf
    • http://muicuiu.dumb1.com/1a01a05a00a05a05a00/Krishna-by-Anant-Pai.pdf
    • http://muicuiu.dumb1.com/6a03a00a09a04a07/The-Dhammapada-by-Swami-Krishna-Prabhu.pdf
    • http://muicuiu.dumb1.com/5a01a06a01a01a05/The-Music-of-Solitude-by-Krishna-Sobti.pdf
    • http://muicuiu.dumb1.com/3a02a00a01a02a03/Krishna-A-Journey-Within-by-Abhishek-Singh.pdf
    • http://muicuiu.dumb1.com/1a09a01a06a04a09/Mahabharata-by-Krishna-Dwaipayana-Vyasa.pdf
    • http://muicuiu.dumb1.com/9a00a00a02a08a09/Krishna-Sinha-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a08a01a05a00a05/The-Dev-Gita-by-Krishna-Dwaipayana-Vyasa.pdf
    • http://muicuiu.dumb1.com/1a09a07a05a00a02/Krishna-The-Defender-of-Dharma-by-Shweta-Taneja.pdf
    • http://muicuiu.dumb1.com/1a00a03a04a07a09a09/V-K-Krishna-Menon-A-Personal-Memoir-by-Janaki.pdf
    • http://muicuiu.dumb1.com/1a05a06a00a02a01/The-Weaver-by-Kai-Strand.pdf
    • http://muicuiu.dumb1.com/1a04a00a07a01a09/Bhagavad-Gita-A-New-Translation-by-Krishna-Dwaipayana-Vyasa.pdf
    • http://muicuiu.dumb1.com/6a08a04a02a01a04/Rabindranath-Tagore-The-Myriad--Minded-Man-by-Krishna-Dutta.pdf
    • http://muicuiu.dumb1.com/1a02a03a01a06a08/Slayer-Of-Kamsa-Krishna-Coriolis-1-by-Ashok-K-Banker.pdf
    • http://muicuiu.dumb1.com/8a09a02a05a07a06/The-Loves-of-Krishna-in-Indian-Painting-and-Poetry-by-W-G-Archer.pdf
    • http://muicuiu.dumb1.com/8a09a02a05a07a03/The-Loves-of-Krishna-in-Indian-Painting-and-Poetry-by-W-G-Archer.pdf
    • http://muicuiu.dumb1.com/1a00a07a03a02a03a07/Fangboy-by-Jeff-Strand.pdf
    • http://muicuiu.dumb1.com/3a09a00a08a04a04/Stalking-You-Now-by-Jeff-Strand.pdf