Malicious PDF — malware analysis report

Static analysis result for SHA-256 67e785bd4e7d0757…

MALICIOUS

PDF

19.0 KB Created: 2019-05-07 03:58:44 +01:00 Authoring application: mPDF 5.7
MD5: 5817f7a3091de840019bab5ef84fa73c SHA-1: 1242494cf4d85cb993024b965898f42ae7a90edf SHA-256: 67e785bd4e7d0757958667373d73987d295c681f96f792ad148c38da520231c8
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, suggesting a tactic to redirect users to external sites. The ML classifier also flagged this PDF as malicious. While the document body is heavily corrupted, the presence of a "download button" heuristic and the link farm indicate an attempt to trick users into navigating to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a00a08a05a08a09/Where-s-Mom-Now-That-I-Need-Her-Surviving-Away-from-Home-by-Kent-P-Frandsen.pdf
    • http://muicuiu.dumb1.com/9a03a07a06a00/Brain-Rules-12-Principles-for-Surviving-and-Thriving-at-Work-Home-and-School-by-John-Medina.pdf
    • http://muicuiu.dumb1.com/4a08a06a05a09a08/Long-Journey-Home-A-Young-Girl-s-Memoir-of-Surviving-the-Holocaust-by-Lucy-Lipiner.pdf
    • http://muicuiu.dumb1.com/7a05a01a04a06a09/Ibsen-Pontoppidan-Og-Arhundredskiftets-Gotik-by-Annemette-Frandsen.pdf
    • http://muicuiu.dumb1.com/9a09a01a02a00a09/Barely-Surviving-Surviving-1-by-Courtney-Cross.pdf
    • http://muicuiu.dumb1.com/4a07a09a07a02a09/Barely-Surviving-Surviving-1-by-Courtney-Cross.pdf
    • http://muicuiu.dumb1.com/1a07a04a02a05a04/Surviving-Surviving-1-by-Michelle-Leigh.pdf
    • http://muicuiu.dumb1.com/6a04a03a01a07/Surviving-the-Fog-Surviving-the-Fog-1-by-Stan-Morris.pdf
    • http://muicuiu.dumb1.com/3a08a02a01a08/Surviving-Raine-Surviving-Raine-1-by-Shay-Savage.pdf
    • http://muicuiu.dumb1.com/7a03a00a03a03/Kent-Family-Chronicles-3-Volumes-in-1-Kent-Family-Chronicles-1-3-by-John-Jakes.pdf
    • http://muicuiu.dumb1.com/1a09a08a06a08a05/Mother-Lode-Stories-of-Home-Life-and-Home-Death-by-Susan-Addison.pdf
    • http://muicuiu.dumb1.com/2a07a06a08a04a05/The-Long-Road-Home-A-Place-Called-Home-3-by-Lori-Wick.pdf
    • http://muicuiu.dumb1.com/7a00a02a01a07a08/The-Book-of-Home-Design-Using-Ikea-Home-Furnishings-by-Anoop-Parikh.pdf
    • http://muicuiu.dumb1.com/7a04a01a00a04a06/Paperless-Home-Organization-How-to-Create-A-Digital-Home-Management-Binder-by-Mystie-Winckler.pdf
    • http://muicuiu.dumb1.com/5a02a00a03a02a03/Super-Natural-Home-Improve-Your-Health-Home-and-Planet--One-Room-at-a-Time-by-Beth-Greer.pdf
    • http://muicuiu.dumb1.com/6a00a01a07a04a08/---Ao-no-Ekusoshisuto-Home-Sweet-Home-Blue-Exorcist-Light-Novel-2-by-Kazue-Kato.pdf
    • http://muicuiu.dumb1.com/4a09a03a03a03a00/Spirit-of-the-Home-How-to-Make-Your-Home-a-Sanctuary-by-Jane-Alexander.pdf
    • http://muicuiu.dumb1.com/4a04a08a05a02a03/Home-Sweet-Home-Hope-Falls-4-by-Melanie-Shawn.pdf
    • http://muicuiu.dumb1.com/1a07a04a04a03a00/Home-Sweet-Home-The-Night-Wars-4-5-by-Missouri-Dalton.pdf
    • http://muicuiu.dumb1.com/6a00a09a03a00a07/The-Home-Exorcist-Curse-Breaking-for-the-Home-by-Percy-Johnson.pdf