Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c1de81bea512754…

MALICIOUS

PDF

19.1 KB Created: 2019-05-03 05:31:54 +01:00 Authoring application: mPDF 5.7
MD5: 22a0b32975193176a97ebadba345b820 SHA-1: 2251c57ff96d17e0f49bd307654b16dee21b5d52 SHA-256: 5c1de81bea512754c34e042efa7c2e21172a2396d7ab88bb83f40ef428c487d4
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, masquerading as book titles, which is a common tactic for SEO spam or phishing. The ML classifier strongly indicated maliciousness, and the heuristic firing confirms the presence of a link farm. No scripts were extracted, but the embedded URLs suggest a potential attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a06a01a00a01a01/Still-Dead-Book-of-the-Dead-2-by-John-Skipp.pdf
    • http://muicuiu.dumb1.com/3a06a00a01a07a03/Zombies-Encounters-with-the-Hungry-Dead-by-John-Skipp.pdf
    • http://muicuiu.dumb1.com/1a00a06a09a03a02a04/Conversations-With-The-Dead-The-Grateful-Dead-Interview-Book-by-David-Gans.pdf
    • http://muicuiu.dumb1.com/4a02a09a05a08a03/True-Blood-Omnibus-2-Dead-to-the-World-Dead-as-a-Doornail-Definitely-Dead-Sookie-Stackhouse-4-6-by-Charlaine-Harris.pdf
    • http://muicuiu.dumb1.com/3a01a09a07a07a00/The-Book-of-the-Dead-Lives-of-the-Justly-Famous-and-the-Undeservedly-Obscure-by-John-Lloyd.pdf
    • http://muicuiu.dumb1.com/4a07a02a02a04a02/The-Book-of-the-Dead-Lives-of-the-Justly-Famous-and-the-Undeservedly-Obscure-by-John-Lloyd.pdf
    • http://muicuiu.dumb1.com/5a08a02a01a00a04/The-Walking-Dead-Book-Twelve-The-Walking-Dead-133-144-by-Robert-Kirkman.pdf
    • http://muicuiu.dumb1.com/2a06a00a08a01/The-Living-Dead-The-Living-Dead-1-by-John-Joseph-Adams.pdf
    • http://muicuiu.dumb1.com/3a05a09a01a09a01/The-Walking-Dead-Book-Seven-The-Walking-Dead-73-84-by-Robert-Kirkman.pdf
    • http://muicuiu.dumb1.com/3a05a09a01a08a03/The-Walking-Dead-Book-Six-The-Walking-Dead-61-72-by-Robert-Kirkman.pdf
    • http://muicuiu.dumb1.com/4a04a01a01a07a07/Living-with-the-Dead-Twenty-Years-on-the-Bus-with-Garcia-and-the-Grateful-Dead-by-Rock-Scully.pdf
    • http://muicuiu.dumb1.com/4a00a01a02a03a09/The-Hungry-Dead-Zombies-Vampires-Ghosts-and-Other-Dead-Things-That-Want-to-Eat-You-by-Lester-Smith.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a03a09/United-States-of-the-Dead-White-Flag-of-the-Dead-4-by-Joseph-Talluto.pdf
    • http://muicuiu.dumb1.com/2a03a00a06a06a05/Dead-by-Midnight-Dead-by-Trilogy-1-Griffin-Powell-11-by-Beverly-Barton.pdf
    • http://muicuiu.dumb1.com/2a08a09a09a02a06/Child-of-a-Dead-God-Noble-Dead-Series-1-6-by-Barb-Hendee.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a02a03/Last-Stand-of-the-Dead-White-Flag-of-the-Dead-6-by-Joseph-Talluto.pdf
    • http://muicuiu.dumb1.com/3a05a09a03a03a00/Dead-Surge-White-Flag-of-the-Dead-5-by-Joseph-Talluto.pdf
    • http://muicuiu.dumb1.com/4a00a06a09a02a00/The-Warring-Dead-In-the-Time-of-the-Dead-2-by-David-Monette.pdf
    • http://muicuiu.dumb1.com/1a05a05a09a02a08/Dead-Line-The-Dead-Series-3-by-Adam-Millard.pdf
    • http://muicuiu.dumb1.com/3a08a09a01a04/Dead-Is-the-New-Black-Dead-Is-1-by-Marlene-Perez.pdf