Malicious PDF — malware analysis report

Static analysis result for SHA-256 6211413a94c70662…

MALICIOUS

PDF

14.0 KB Created: 2019-04-30 18:54:50 +01:00 Authoring application: mPDF 5.7
MD5: c1530080789a2d7a7846c05c8b4e4340 SHA-1: be1bb29d4148f69d385f55f3f2f65b06c499852c SHA-256: 6211413a94c706625e21b2aa53072130fc0fcfe9d38f7b9f65d7309d83101c16
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the document body is heavily corrupted, the presence of these links and the ML classifier's high confidence score indicate a malicious intent to direct users to external resources. The SE_DOWNLOAD_BUTTON heuristic further suggests a lure to encourage user interaction with these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a09a05a07a06a04/Cam-Jansen-and-the-Mystery-of-the-Television-Dog-Cam-Jansen-Mysteries-4-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/1a02a05a09a04a08/Defect-by-Ryann-Kerekes.pdf
    • http://muicuiu.dumb1.com/2a02a00a00a07a00/Raising-Ryann-Bad-Boy-Reformed-1-by-Alyssa-Rae-Taylor.pdf
    • http://muicuiu.dumb1.com/4a07a09a09a01a05/Cards-of-Love-The-High-Priestess-by-Olivia-Ryann.pdf
    • http://muicuiu.dumb1.com/1a05a03a02a01a04/His-Name-In-Lights-by-Patty-Jansen.pdf
    • http://muicuiu.dumb1.com/1a08a01a01a09a02/Cam-Jansen-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/9a00a03a04a01a06/Amaryllis-of-Hawaii-by-Marilyn-Jansen.pdf
    • http://muicuiu.dumb1.com/3a05a02a09a09a09/Shifting-Reality-by-Patty-Jansen.pdf
    • http://muicuiu.dumb1.com/2a08a05a06a01a05/How-I-Became-a-Fearless-Woman-by-Pamela-Jansen.pdf
    • http://muicuiu.dumb1.com/7a09a09a01a01/The-Mystery-of-the-UFO-Cam-Jansen-Mysteries-2-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/2a03a09a08a06a07/Fire-amp-Ice-Icefire-Trilogy-1-by-Patty-Jansen.pdf
    • http://muicuiu.dumb1.com/9a08a08a08a06a02/The-Mystery-of-the-Television-Dog-Cam-Jansen-Mysteries-4-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/2a00a08a05a02a09/The-Birthday-Mystery-Cam-Jansen-Mysteries-20-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/4a03a00a09a00a03/The-Bittersweet-by-Ana-Patrick.pdf
    • http://muicuiu.dumb1.com/2a00a08a05a03a01/The-Mystery-of-the-Stolen-Diamonds-Cam-Jansen-Mysteries-1-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/4a05a02a02a01a01/The-Mystery-of-the-Gold-Coins-Cam-Jansen-Mysteries-5-by-David-A-Adler.pdf
    • http://muicuiu.dumb1.com/1a06a00a07a06a07/Steel-Beneath-the-Skin-Aneka-Jansen-1-by-Niall-Teasdale.pdf
    • http://muicuiu.dumb1.com/9a00a04a08a07a01/Percy-s-Plan-Berkshires-Journal-Series-1-by-Paul-Jansen.pdf
    • http://muicuiu.dumb1.com/5a00a02a00a05a02/Bittersweet-by-Penelope-Fletcher.pdf
    • http://muicuiu.dumb1.com/4a01a02a08a08/Bittersweet-by-Sarah-Ockler.pdf