Malicious PDF — malware analysis report

Static analysis result for SHA-256 699ff167887e3fbb…

MALICIOUS

PDF

15.3 KB Created: 2019-04-30 04:08:58 +01:00 Authoring application: mPDF 5.7
MD5: 3faed9fae3d1416790f30e85b8553f95 SHA-1: efb0500871c4dde428e3acc28e22184f9b0cb85a SHA-256: 699ff167887e3fbb3860ee8bce02171dfb516b4ee965f9d37611138104497b5f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm, which is a common technique for distributing malicious content or leading users to phishing sites. The ML classifier also flagged this PDF as malicious with high confidence. The presence of a 'download button' heuristic further supports the lure-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a09a01a03a00a06/City-of-the-Fallen-Dark-Tides-1-by-Diana-Bocco.pdf
    • http://muicuiu.dumb1.com/3a04a03a01a09a03/Midnight-Tides-The-Malazan-Book-of-the-Fallen-5-by-Steven-Erikson.pdf
    • http://muicuiu.dumb1.com/1a09a08a09a03a06/Dark-Tides-by-Chris-Ewan.pdf
    • http://muicuiu.dumb1.com/1a09a06a05a00a08/Love-in-a-Fallen-City-by-Eileen-Chang.pdf
    • http://muicuiu.dumb1.com/3a05a08a07a05a01/City-of-Fallen-Angels-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/3a07a03a06a01a01/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/2a01a02a06a07a07/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/7a02a06a04a00a02/City-of-Fallen-Angels-Chroniken-der-Unterwelt-4-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/7a09a06a00a08a08/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/7a04a05a02a00/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://muicuiu.dumb1.com/3a08a02a02a07a02/The-Forbidden-Fortress-Omega-City-2-by-Diana-Peterfreund.pdf
    • http://muicuiu.dumb1.com/2a04a03a02a02a04/His-Dark-Bond-Fallen-2-by-Anne-Marsh.pdf
    • http://muicuiu.dumb1.com/4a08a03a05a06a08/Welcome-to-the-Dark-Side-The-Fallen-Men-2-by-Giana-Darling.pdf
    • http://muicuiu.dumb1.com/1a07a00a00a03a09/Fallen-Angel-Darkside-Trilogy-1-by-Dark-Scribe.pdf
    • http://muicuiu.dumb1.com/7a09a04a06a04a05/Dark-Vengeance-Charmed-15-by-Diana-G-Gallagher.pdf
    • http://muicuiu.dumb1.com/2a00a01a05a05a08/The-Sting-of-Victory-A-Dark-Fantasy-Lesbian-Romance-Fallen-Gods-Book-1-by-S-D-Simper.pdf
    • http://muicuiu.dumb1.com/9a05a05a02/Leaving-Lavender-Tides-Lavender-Tides-1-5-by-Colleen-Coble.pdf
    • http://muicuiu.dumb1.com/1a09a06a03a01a00/Trace-of-Magic-Diamond-City-Magic-1-by-Diana-Pharaoh-Francis.pdf
    • http://muicuiu.dumb1.com/1a01a05a07a06a05a06/Mystic-Tides-Mystic-Tides-1-by-Kate-Allenton.pdf
    • http://muicuiu.dumb1.com/2a03a02a08a05a06/Fallen-Prince-Fallen-Trilogy-book-1-by-Tess-Williams.pdf