Malicious PDF — malware analysis report

Static analysis result for SHA-256 621655975597f537…

MALICIOUS

PDF

22.0 KB Created: 2019-04-25 00:48:46 +01:00 Authoring application: mPDF 5.7
MD5: 49c779b33d3d0e7e112b7273f233bde1 SHA-1: b8cc8c0130ee18fee57a5d7641b8d384d48ea2f3 SHA-256: 621655975597f537972b414167200cfb11952672f9b73475efe38b5ed6b35783
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to direct users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also flagged the sample with high confidence. The SE_DOWNLOAD_BUTTON heuristic indicates a potential lure to trick users into clicking these links. The primary purpose appears to be facilitating the download of further malicious payloads or redirecting users to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a03a03a00a08a09/Faerie-Queene-The-Mutability-Cantos-and-Selections-from-the-Minor-Poems-Bks-1-and-2-by-Edmund-Spenser.pdf
    • http://muicuiu.dumb1.com/4a01a02a08a02/The-Faerie-Queene-by-Edmund-Spenser.pdf
    • http://muicuiu.dumb1.com/1a00a08a01a09a08a06/Die-Gleichnisse-In-Edmund-Spenser-s-Faerie-Queene-Und-Ihre-Vorbilder-by-Wilhelm-Heise.pdf
    • http://muicuiu.dumb1.com/6a00a03a09a04a07/Una-and-the-Red-Cross-Knight-and-Other-Tales-from-Spenser-s-Faery-Queene-by-Edmund-Spenser.pdf
    • http://muicuiu.dumb1.com/9a03a01a00a07a02/Spenser-und-das-gestohlene-Manuskript-Ein-Auftrag-f-r-Spenser-by-Robert-B-Parker.pdf
    • http://muicuiu.dumb1.com/2a02a02a03a08a05/Selections-from-Dreamsongs-3-Selections-from-Wild-Cards-and-More-Stories-from-Martin-s-Later-Years-Unabridged-Selections-by-George-R-R-Martin.pdf
    • http://muicuiu.dumb1.com/1a00a00a00a04a09a07/Milton-s-Minor-Poems-L-Allegro-Il-Penseroso-Comus-and-Lycidas-by-John-Milton.pdf
    • http://muicuiu.dumb1.com/2a03a09a04a00a07/Lament-The-Faerie-Queen-s-Deception-Books-of-Faerie-1-by-Maggie-Stiefvater.pdf
    • http://muicuiu.dumb1.com/7a08a01a03a05a06/Muslihat-Ratu-Peri---Lament-The-Faerie-Queen-s-Deception-Books-of-Faerie-1-by-Maggie-Stiefvater.pdf
    • http://muicuiu.dumb1.com/2a05a08a07a07a05/Ballad-A-Gathering-of-Faerie-Books-of-Faerie-2-by-Maggie-Stiefvater.pdf
    • http://muicuiu.dumb1.com/1a00a00a00a04a04a05/Milton-Minor-Poems-L-Allegro-Arcades-On-Shakespeare-Il-Penseroso-On-the-Nativity-At-a-Solemn-Music-Comus-Lycidas-Sonnets-by-John-Milton.pdf
    • http://muicuiu.dumb1.com/4a01a06a04a01a03/The-Golden-Book-of-Faerie-The-Chronicles-of-Faerie-1-4-by-O-R-Melling.pdf
    • http://muicuiu.dumb1.com/2a09a08a04a06a07/Wendell-Minor-Twenty-Five-Years-Of-Book-Cover-Art-by-Wendell-Minor.pdf
    • http://muicuiu.dumb1.com/1a06a02a07a07a09/Druids-of-the-Faerie-Baytel-and-the-Goblin-Horde-Druids-of-the-Faerie-2-by-Lewis-G-Gazoul.pdf
    • http://muicuiu.dumb1.com/1a06a03a00a04a02/Druids-of-the-Faerie-Gather-the-Champions-Druids-of-the-Faerie-1-by-Lewis-G-Gazoul.pdf
    • http://muicuiu.dumb1.com/3a08a06a07a09a06/The-Faerie-Path-Faerie-Path-1-by-Allan-Frewin-Jones.pdf
    • http://muicuiu.dumb1.com/3a01a08a08a05a07/Queene-of-Light-by-Jennifer-Armintrout.pdf
    • http://muicuiu.dumb1.com/3a06a03a05a02/The-Cantos-by-Ezra-Pound.pdf
    • http://muicuiu.dumb1.com/2a01a00a06a02a03/The-Tragedy-of-Dido-Queene-of-Carthage-by-Christopher-Marlowe.pdf
    • http://muicuiu.dumb1.com/1a03a07a09a06a02/The-Pisan-Cantos-by-Ezra-Pound.pdf