Malicious PDF — malware analysis report

Static analysis result for SHA-256 5cc3ae76a2854a12…

MALICIOUS

PDF

22.5 KB Created: 2019-04-30 04:30:05 +01:00 Authoring application: mPDF 5.7
MD5: 7d8c3e165e4ff1a57bcc5a026137a1d8 SHA-1: 3f7e1af5982b1bf0abb042e9c386ee6a7ceffaff SHA-256: 5cc3ae76a2854a128194818352b5948d084cebdf88f3328d272c43760124d1be
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common technique for distributing malicious content or redirecting users to phishing sites. Although no scripts were explicitly extracted, the PDF structure and the heuristic firings suggest an attempt to exploit users through a deceptive download lure. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a01a06a09a01a05/Jesus-Son-Stories-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/2a03a04a06a03/Tree-of-Smoke-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/2a04a01a05a08a03/The-Incognito-Lounge-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/4a05a05a04a08a03/Resuscitation-of-a-Hanged-Man-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/1a05a07a00a06a07/The-Throne-of-the-Third-Heaven-of-the-Nations-Millennium-General-Assembly-Poems-Collected-and-New-by-Denis-Johnson.pdf
    • http://muicuiu.dumb1.com/1a00a05a09a00a02a07/Tell-Me-the-Stories-of-Jesus-The-Parables-for-Children-by-Nancy-Regensburger.pdf
    • http://muicuiu.dumb1.com/2a04a04a01a05a08/Book-of-Mormon-Stories-by-The-Church-of-Jesus-Christ-of-Latter-day-Saints.pdf
    • http://muicuiu.dumb1.com/1a07a08a01a04a04/Jesus-Freaks-Stories-of-Revolutionaries-Who-Changed-Their-World-Fearing-God-Not-Man-by-D-C-Talk.pdf
    • http://muicuiu.dumb1.com/4a02a02a02a04a01/Revisiting-the-Parables-of-Jesus-Ancient-stories-contemporary-audience-by-Lisa-L-pez-Smith.pdf
    • http://muicuiu.dumb1.com/2a02a07a00a02a02/Irregular-Verbs-and-Other-Stories-by-Matthew-Johnson.pdf
    • http://muicuiu.dumb1.com/1a09a06a04a08a06/Wild-Grass-Three-Stories-of-Change-in-Modern-China-by-Ian-Johnson.pdf
    • http://muicuiu.dumb1.com/1a01a06a05a04a08a04/Time-To-Put-Your-Feet-Up-7-stories-and-biscuit-recipes-to-relax-with-by-Sue-Johnson.pdf
    • http://muicuiu.dumb1.com/1a08a08a09a05a08/Bedtime-Stories-A-Collection-of-Erotic-Fairy-Tales-by-Jean-Johnson.pdf
    • http://muicuiu.dumb1.com/4a02a06a07a05a09/The-Adventures-of-Harold-and-the-Purple-Crayon-Four-Magical-Stories-by-Crockett-Johnson.pdf
    • http://muicuiu.dumb1.com/9a09a09a07a02a05/Jesus-Firsthand-Daily-Devotional-Meditations-for-Knowing-Jesus-by-David-Feddes.pdf
    • http://muicuiu.dumb1.com/1a08a09a09a08a02/Sitting-at-the-Feet-of-Rabbi-Jesus-How-the-Jewishness-of-Jesus-Can-Transform-Your-Faith-by-Ann-Spangler.pdf
    • http://muicuiu.dumb1.com/3a06a07a00a07a03/What-Would-Jesus-Really-Do-The-Power-amp-Limits-of-Jesus-Moral-Teachings-by-Andrew-Fiala.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a00a05a03/The-Jesus-Mystery-Astonishing-Clues-to-the-True-Identities-of-Jesus-and-Paul-by-Lena-Einhorn.pdf
    • http://muicuiu.dumb1.com/5a06a02a06a00a03/J-sus-Fils-de-l-Homme-J-sus-the-Son-of-Man-by-Kahlil-Gibran.pdf
    • http://muicuiu.dumb1.com/1a01a06a02a06a07a00/Weihnachten-feiern-Dass-Jesus-j-disch-gelebt-hat-wird-totgeschwiegen-So-hat-sich-Jesus-das-nicht-vorgestellt-Denken-Sie-dar-ber-nach-by-Avraham-Kopilowicz.pdf