Malicious PDF — malware analysis report

Static analysis result for SHA-256 6bd64c3afb178cb4…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 05:40:18 +01:00 Authoring application: mPDF 5.7
MD5: 7f7932ce594b74d9820ce596f845c70f SHA-1: c89dbd68f307915cfa7f7598bad235e1936a96d0 SHA-256: 6bd64c3afb178cb4508b6a8da777cea4b841e77b5bd09b1b253dd9e8f13dfe7d
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. While the ML classifier flagged it as malicious with high confidence, the specific intent appears to be the distribution of numerous book-related PDFs, likely for SEO manipulation or to lead users to potentially malicious content. No scripts were extracted, but the presence of many links suggests a phishing or content-luring attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a06a08a06a04a06/Charisme-Comment-Devenir-Plus-Charismatique-by-Steve-Lupin.pdf
    • http://muicuiu.dumb1.com/6a06a08a07a05a09/CULTIVEZ-VOTRE-CHARISME-COMMENT-D-VELOPPER-VOTRE-POUVOIR-DE-CONVICTION-by-Chilina-Hills.pdf
    • http://muicuiu.dumb1.com/5a07a07a09a07a08/4-heures-par-semaine-pour-un-corps-d-enfer-Perte-de-poids-performances-sexuelles-comment-devenir-un-surhomme-by-Timothy-Ferriss.pdf
    • http://muicuiu.dumb1.com/7a07a02a06a06/Ars-ne-Lupin-Gentleman-Thief-Ars-ne-Lupin-1-by-Maurice-Leblanc.pdf
    • http://muicuiu.dumb1.com/6a06a08a06a03a04/Le-charisme-d-mythifi-by-Olivia-Fox-Cabane.pdf
    • http://muicuiu.dumb1.com/1a00a07a09a05a03a04/Sanguine-Abgrund-by-Max-Lupin.pdf
    • http://muicuiu.dumb1.com/3a03a07a08a02a07/New-Lupin-III-World-s-Most-Wanted-by-Monkey-Punch.pdf
    • http://muicuiu.dumb1.com/2a07a07a00a02a07/The-Exploits-of-Ars-ne-Lupin-by-Maurice-Leblanc.pdf
    • http://muicuiu.dumb1.com/1a08a04a03a09a07/The-Dark-Lady-Sherlock-Lupin-and-Me-1-by-Irene-Adler.pdf
    • http://muicuiu.dumb1.com/6a01a02a01a04a01/Devenir-acteur-by-Gregory-Alexandre.pdf
    • http://muicuiu.dumb1.com/6a01a02a00a09a06/Devenir-Maigre-by-Eric-Dassonville.pdf
    • http://muicuiu.dumb1.com/6a01a02a02a00a03/Devenir-biographe-by-Florence-CLERFEUILLE.pdf
    • http://muicuiu.dumb1.com/6a01a02a02a00a04/Devenir-champion-by-C-dric-QUIGNON-FLEURET.pdf
    • http://muicuiu.dumb1.com/6a01a02a00a08a09/Beyond-Chemo-Brain-Recovering-after-Surviving-by-Carol-Devenir.pdf
    • http://muicuiu.dumb1.com/7a04a05a08a00a07/100-Conseils-pour-devenir-enceinte-rapidement-by-Romain-GARNIER.pdf
    • http://muicuiu.dumb1.com/6a08a05a07a01a00/La-drogue-dans-mes-veines-mes-enfants-dans-la-peau-L-extraordinaire-histoire-d-une-femme-qui-voulait-devenir-ordinaire-by-Samanta-Borzi.pdf
    • http://muicuiu.dumb1.com/3a06a04a07a08a09/The-Crocodile-Hunter-The-Incredible-Life-and-Adventures-of-Steve-and-Terri-Irwin-by-Steve-Irwin.pdf
    • http://muicuiu.dumb1.com/6a00a06a06a03a09/Steve-Jobs-50-Life-and-Business-Lessons-from-Steve-Jobs-by-George-Ilian.pdf
    • http://muicuiu.dumb1.com/4a09a05a04a06a02/Last-Dog-on-the-Hill-The-Unforgettable-Story-of-Lou-Best-Friend-and-Hero-Steve-Duno-by-Steve-Duno.pdf
    • http://muicuiu.dumb1.com/6a08a07a02a04a07/Off-The-Beaten-Path---A-Steve-Cassidy-Mystery-Steve-Cassidy-3-by-John-Schlarbaum.pdf