Malicious PDF — malware analysis report

Static analysis result for SHA-256 638ee008e9674ba6…

MALICIOUS

PDF

19.3 KB Created: 2019-04-30 02:39:00 +01:00 Authoring application: mPDF 5.7
MD5: e12f2c8dbdbc8cb31f0ac2d83a44976c SHA-1: 55cf30437966f8793c0b24284ef58a3bbcb2f209 SHA-256: 638ee008e9674ba68ca0bd225fbd0f5456c0ea1f31c91a1be947b8e5377419e1
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm, which is a common technique for SEO manipulation or distributing malicious content. While the document body is heavily corrupted, the presence of a PDF_SEO_LINK_FARM heuristic firing and numerous embedded URLs strongly suggests a malicious intent to redirect users to potentially harmful sites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a08a05a09a07a08/Moon-Shot-The-Inside-Story-of-America-s-Race-to-the-Moon-by-Alan-Shepard.pdf
    • http://muicuiu.dumb1.com/2a01a07a04a05a07/Light-This-Candle-The-Life-amp-Times-of-Alan-Shepard--America-s-First-Spaceman-by-Neal-Thompson.pdf
    • http://muicuiu.dumb1.com/2a06a06a05a01a08/The-Moon-of-Gomrath-by-Alan-Garner.pdf
    • http://muicuiu.dumb1.com/3a01a06a04a03a03/Racing-the-Moon-by-Alan-Armstrong.pdf
    • http://muicuiu.dumb1.com/5a04a01a03a03/Fatal-Storm-The-Inside-Story-of-the-Tragic-Sydney-Hobart-Race-by-Rob-Mundle.pdf
    • http://muicuiu.dumb1.com/3a02a08a01a02a00/Mrs-Darley-s-Moon-Mysteries-A-Celebration-Of-Moon-Lore-And-Magic-by-Carole-Carlton.pdf
    • http://muicuiu.dumb1.com/9a06a02a01a02a09/Moon-O-Theism-Religion-of-a-War-and-Moon-God-Prophet-Volume-I-of-II-by-Yoel-Natan.pdf
    • http://muicuiu.dumb1.com/1a08a08a05a03a06/Desert-Moon-The-Wolves-of-Twin-Moon-Ranch-1-by-Anna-Lowe.pdf
    • http://muicuiu.dumb1.com/1a02a00a01a07a02/Blood-Moon-Dark-Moon-Series-Book-1-by-Shelly-M-Burrows.pdf
    • http://muicuiu.dumb1.com/3a08a07a06a02a06/In-the-Light-of-the-Full-Cold-Moon-Moon-Sage-Theosophies-1-by-Susan-Elizabeth-Girard.pdf
    • http://muicuiu.dumb1.com/6a04a04a01a08a02/The-Adventures-of-Tintin-Vol-5-Land-of-Black-Gold-Destination-Moon-Explorers-on-the-Moon-by-Herg-.pdf
    • http://muicuiu.dumb1.com/4a09a06a04a06a08/Full-Moon-The-Amazing-Rock-and-Roll-Life-of-Keith-Moon-by-Dougal-Butler.pdf
    • http://muicuiu.dumb1.com/2a03a08a07a01a07/American-Eclipse-A-Nation-s-Epic-Race-to-Catch-the-Shadow-of-the-Moon-and-Win-the-Glory-of-the-World-by-David-Baron.pdf
    • http://muicuiu.dumb1.com/4a02a09a09a03a00/Moon-Signs-Moon-Mystery-1-by-Helen-Haught-Fanick.pdf
    • http://muicuiu.dumb1.com/2a08a03a06a00a09/Moon-Shimmers-Otherworld-Sisters-of-the-Moon-19-by-Yasmine-Galenorn.pdf
    • http://muicuiu.dumb1.com/1a03a05a04a03a03/Moon-of-the-Terrible-Seasons-of-the-Moon-Cain-Chronicles-3-by-S-M-Reine.pdf
    • http://muicuiu.dumb1.com/1a08a09a04a05a09/To-Crave-a-Blood-Moon-Moon-Chasers-3-by-Sharie-Kohler.pdf
    • http://muicuiu.dumb1.com/8a07a02a03a08a08/Full-Moon-Lockdown-Moon-Compound-1-by-Jackie-Nacht.pdf
    • http://muicuiu.dumb1.com/4a07a09a04a00a07/Moon-Ghostie-Manners-Moon-Ghosties-1-by-Pauline-Brasch.pdf
    • http://muicuiu.dumb1.com/9a01a02a02a03/Moon-Burning-Children-of-the-Moon-3-by-Lucy-Monroe.pdf