Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fb91f3b26324abd…

MALICIOUS

PDF

12.1 KB Created: 2019-05-07 04:30:05 +01:00 Authoring application: mPDF 5.7
MD5: 8d139ccbe391af491e33712ceff6ccaa SHA-1: fc2f106fbeaf462f15d9bbc6bbda7b41e3053cf2 SHA-256: 5fb91f3b26324abd3377014a529cdcead7dd74130ee719a0a4f9679f2bbed705
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, identified as a link farm. While the document body is heavily corrupted, the presence of numerous links and a 'download button' heuristic suggests a lure to download or view these linked documents. The ML classifier also flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8737

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a09a03a09a05a04/Kobra-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a07a04a00a01a07/The-Libertines-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a00a04a07a02a07/Son-of-Maryam-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a00a08a08a03a03/Souterrain-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a01a09a04a01a01/Minuscule-801-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a04a02a06a06a00/Nalle-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a03a05a03a03a08/Son-Pari-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a05a08a00a06a05/The-Rasmus-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a03a02a08a08a05/The-Silmarillion-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a04a02a02/Greystones-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a02a03a08a08a01/The-Dickies-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/5a06a06a05a06a05/The-Decalogue-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a00a00a04a03a09/Lucio-Wagner-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a01a06a07a03a07a07/Third-Treaty-of-San-Ildefonso-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a05a07a04a06a05/Catherine-of-Cleves-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a00a00a00/Uhtred-the-Bold-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a02a02a08a04a03/Edict-of-Nantes-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a00a05a06a03a09/Comte-de-Lautreamont-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a07a07a07a07a02/Frans-Wildenhain-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a07a08a07a08a00/Hartwig-of-Uthlede-by-Jesse-Russell.pdf