Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e6780a217ccf002…

MALICIOUS

PDF

15.4 KB Created: 2019-04-29 23:03:35 +01:00 Authoring application: mPDF 5.7
MD5: 214b955d4033b76f9639667bbb1697ff SHA-1: 7cd7a0ac11d6b3ffe3bbe8cb8032575a89fa395e SHA-256: 5e6780a217ccf002063cea4c085cd6f135d48c4a0461a7233e8b6ac070ad4726
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the document body text is heavily corrupted, the presence of numerous links suggests a malicious intent to redirect users to potentially harmful content or to manipulate search engine results. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a02a03a02a04a03/Singin-and-Swingin-and-Gettin-Merry-Like-Christmas-Maya-Angelou-s-Autobiography-3-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/2a00a00a01a03a07/Mom-amp-Me-amp-Mom-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/8a05a08a02a07/Gather-Together-in-My-Name-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/2a06a06a02a00a08/And-Still-I-Rise-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/6a06a06a00a08a09/Phenomenal-Woman-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/2a05a09a08a05a02/Maya-Angelou-by-Lisbeth-Kaiser.pdf
    • http://muicuiu.dumb1.com/3a09a08a03a08a02/Letter-to-My-Daughter-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/9a08a07a00a08/All-God-s-Children-Need-Traveling-Shoes-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/9a02a00a03a02/The-Complete-Collected-Poems-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/3a02a04a08a08/I-Know-Why-the-Caged-Bird-Sings-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/1a05a06a03a03a05/A-Song-Flung-Up-To-Heaven-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/6a00a08a02a04/I-Know-Why-the-Caged-Bird-Sings-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/5a07a04a05a07a02/Io-so-perch-canta-l-uccello-in-gabbia-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/1a05a06a07a04a00/Celebrations-Rituals-of-Peace-and-Prayer-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/4a07a09a02a03/Phenomenal-Woman-Four-Poems-Celebrating-Women-by-Maya-Angelou.pdf
    • http://muicuiu.dumb1.com/5a00a01a09a08a03/The-Mountains-Moved-by-A-H-Parr.pdf
    • http://muicuiu.dumb1.com/3a03a04a01a09a06/The-Bed-Moved-Stories-by-Rebecca-Schiff.pdf
    • http://muicuiu.dumb1.com/2a02a08a04a05a01/Who-Moved-My-Cheese-For-Kids-by-Spencer-Johnson.pdf
    • http://muicuiu.dumb1.com/9a07a02a04a00/Who-Moved-My-Cheese-For-Teens-by-Spencer-Johnson.pdf
    • http://muicuiu.dumb1.com/4a07a00a01a00/The-Moved-Outers-by-Florence-Crannell-Means.pdf