Malicious PDF — malware analysis report

Static analysis result for SHA-256 63e79c21caf4290a…

MALICIOUS

PDF

14.5 KB Created: 2019-05-02 01:00:22 +01:00 Authoring application: mPDF 5.7
MD5: c2ce5c2ebf150126de6d1cdf5a4cf314 SHA-1: f9fe5bac149691390655f3511c20c066892585c5 SHA-256: 63e79c21caf4290af60450f2309be172b40052f21458719af8d4b09a214ce6ee
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as confirmed benign, the sheer volume and the nature of the heuristic suggest a potential attempt to manipulate search engine results or direct users to a large collection of documents. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a00a05a04a04a02/Robert-Orme-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a01a06a08a06a05a04/Robert-Maxwell-1st-Earl-of-Farnham-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a09a02a04a05a01/Bishops-of-Hereford-Ealdred-Edmund-Bonner-William-Courtenay-Gilbert-Foliot-Bishop-of-Hereford-Gerard-Robert-de-Bethune-Robert-of-Melun-by-Source-Wikipedia.pdf
    • http://muicuiu.dumb1.com/6a09a02a02a04a08/Interpretation-of-Scripture-Theory-A-Selection-of-Works-of-Hugh-Andrew-Richard-and-Godfrey-of-St-Victor-and-of-Robert-of-Melun-by-Franklin-T-Harkins.pdf
    • http://muicuiu.dumb1.com/9a03a02a08a08a05/The-Silmarillion-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a00a08a08a03a03/Souterrain-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/5a06a06a05a06a05/The-Decalogue-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a03a05a03a03a08/Son-Pari-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a07a04a00a01a07/The-Libertines-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a00a04a07a02a07/Son-of-Maryam-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a01a09a04a01a01/Minuscule-801-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a05a08a00a06a05/The-Rasmus-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a09a03a09a05a04/Kobra-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a09a04a04a02a02/Greystones-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/7a02a03a08a08a01/The-Dickies-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/9a04a02a06a06a00/Nalle-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a01a06a03a05a05/Adalbert-of-Hamburg-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/6a00a00a04a03a09/Lucio-Wagner-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/8a05a02a07a04a06/Battle-of-Lutter-by-Jesse-Russell.pdf
    • http://muicuiu.dumb1.com/1a00a02a00a09a09a09/Waris-Hussein-by-Jesse-Russell.pdf