Malicious PDF — malware analysis report

Static analysis result for SHA-256 695085af3a8ce344…

MALICIOUS

PDF

15.5 KB Created: 2019-05-07 03:31:03 +01:00 Authoring application: mPDF 5.7
MD5: 876e75801b0d9da7f348b8c17d3f66ff SHA-1: 6ab9ec17316e032437792ec3d0f17327fa70050b SHA-256: 695085af3a8ce344760beb65cf24a1ec0af12020156a7c4c9708e87ece69caef
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. While the document body is heavily obfuscated, the presence of these links and the ML classifier's high confidence score suggest a malicious intent to redirect users to potentially harmful content. The links themselves appear to be part of a scheme to generate traffic or manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a05a06a03a05a02/Sugar-Sugar-Rune-Volume-4-Sugar-Sugar-Rune-4-by-Moyoco-Anno.pdf
    • http://muicuiu.dumb1.com/6a05a06a03a05a04/Sugar-Sugar-Rune-Volume-8-Sugar-Sugar-Rune-8-by-Moyoco-Anno.pdf
    • http://muicuiu.dumb1.com/3a08a07a02/Sugar-Rush-Sugar-Bowl-2-by-Sawyer-Bennett.pdf
    • http://muicuiu.dumb1.com/9a05a06a00a00a04/Low-Sugar-So-Simple-100-Delicious-Low-Sugar-Low-Carb-Gluten-Free-Recipes-for-Eating-Clean-and-Living-Healthy-by-Elviira-Krebber.pdf
    • http://muicuiu.dumb1.com/7a01a02a01a01a07/White-Sugar-Brown-Sugar-by-E-G-Tripp.pdf
    • http://muicuiu.dumb1.com/2a07a03a05a00a05/Sugar-Rush-Sugar-1-by-Julie-Burchill.pdf
    • http://muicuiu.dumb1.com/2a07a07a01a03a04/Sugar-Princess-Skating-To-Win-Vol-1-Sugar-Princess-1-by-Hisaya-Nakajo.pdf
    • http://muicuiu.dumb1.com/2a03a04a01a09a00/Deadly-Sugar-Deadly-Sugar-1-by-Ofelia-Gr-nd.pdf
    • http://muicuiu.dumb1.com/6a04a05a05a03a01/The-Sugar-Babies-The-Sugar-Babies-1-by-O-M-Faye.pdf
    • http://muicuiu.dumb1.com/1a00a08a04a09a00a04/FROM-SUGAR-TO-SHIT-2-by-Mr-777.pdf
    • http://muicuiu.dumb1.com/1a01a05a07a00/Sugar-Springs-Sugar-Springs-1-by-Kim-Law.pdf
    • http://muicuiu.dumb1.com/3a01a07a00a01a05/The-Chameleon-by-Sugar-Rautbord.pdf
    • http://muicuiu.dumb1.com/4a06a06a08a08a08/Sugar-for-the-Horse-by-H-E-Bates.pdf
    • http://muicuiu.dumb1.com/5a00a03a05a00a03/Sugar-Topped-by-E-Davies.pdf
    • http://muicuiu.dumb1.com/3a02a01a07a05a00/The-Bad-Boy-CEO-Destiny-1-by-Sugar-Jamison.pdf
    • http://muicuiu.dumb1.com/4a07a00a06a07a04/Year-of-No-Sugar-by-Eve-O-Schaub.pdf
    • http://muicuiu.dumb1.com/1a09a08a09a06a00/Sugar-amp-Spice-by-Saffina-Desforges.pdf
    • http://muicuiu.dumb1.com/2a02a04a06a04a06/The-Sugar-Divorce-by-Suzanna-Stinnett.pdf
    • http://muicuiu.dumb1.com/1a05a01a00a04a00/The-Sugar-House-by-Jean-Scheffler.pdf
    • http://muicuiu.dumb1.com/9a02a07a04a00/Hannah-and-Sugar-by-Kate-Berube.pdf