Malicious PDF — malware analysis report

Static analysis result for SHA-256 609ecf34910f88ec…

MALICIOUS

PDF

17.9 KB Created: 2019-05-05 15:47:08 +01:00 Authoring application: mPDF 5.7
MD5: 7a41dbc44ae47f39d9dd81724e462968 SHA-1: b516e2d1471d5841e514c3cd3824f682b1c25417 SHA-256: 609ecf34910f88ec2c009577fff708adbeb75d2939851d280b626e5b916bd054
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic 'PDF_SEO_LINK_FARM' indicate a malicious intent to manipulate search engine results or distribute content through a deceptive structure. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a08a03a02a00a09/Through-the-Closet-Door-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/3a05a07a04a04a01/Rick-Steves-Europe-Through-the-Back-Door-2015-The-Travel-Skills-Handbook-by-Rick-Steves.pdf
    • http://muicuiu.dumb1.com/4a05a07a04a04a04/How-I-Met-My-Man-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/4a01a03a08a07a08/Legally-Wed-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/2a02a08a01a04a03/Bashed-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/2a08a06a08a05a09/Caregiver-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/6a05a05a05/Rick-Steves-Europe-Through-the-Back-Door-by-Rick-Steves.pdf
    • http://muicuiu.dumb1.com/4a01a04a08a04a01/Mute-Witness-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/3a05a03a01a08a05/A-Demon-Inside-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/2a06a09a04a09a00/No-Way-Back-Tom-Reed-and-Walt-Sydowski-4-by-Rick-Mofina.pdf
    • http://muicuiu.dumb1.com/1a04a04a07a02a07/If-Angels-Fall-Tom-Reed-and-Walt-Sydowski-1-by-Rick-Mofina.pdf
    • http://muicuiu.dumb1.com/1a01a07a00a03a05/A-Face-Without-a-Heart-A-Modern-Day-Version-of-Oscar-Wilde-s-the-Picture-of-Dorian-Gray-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/6a08a03a02a01a02/Shop-Your-Closet-The-Ultimate-Guide-to-Organizing-Your-Closet-with-Style-by-Melanie-Charlton-Fascitelli.pdf
    • http://muicuiu.dumb1.com/1a09a06a05a02a05/Chaser-Chaser-1-by-Rick-R-Reed.pdf
    • http://muicuiu.dumb1.com/8a05a08a06a07a02/The-Lazarus-Door-Who-would-choose-a-door-over-a-man-like-him-by-S-E-Lentz.pdf
    • http://muicuiu.dumb1.com/1a06a03a09a00a03/Todd-And-Brad-Reed-s-Michigan-Wednesdays-in-the-Mitten-by-Todd-Reed.pdf
    • http://muicuiu.dumb1.com/8a01a06a03a03a09/Door-to-Door-by-Mariam-Razek.pdf
    • http://muicuiu.dumb1.com/1a00a01a01a02a04a08/Rick-Steves-Mona-Winks-Self-Guided-Tours-of-Europe-s-Top-Museums-by-Rick-Steves.pdf
    • http://muicuiu.dumb1.com/1a00a08a02a02a02a00/Rick-Steves-Tour-Hofburg-Imperial-Apartments-Vienna-by-Rick-Steves.pdf
    • http://muicuiu.dumb1.com/5a05a09a08a03a08/Uncanny-X-Force-by-Rick-Remender-The-Complete-Collection-Volume-1-by-Rick-Remender.pdf