Malicious PDF — malware analysis report

Static analysis result for SHA-256 741d70a16139123b…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 04:47:13 +01:00 Authoring application: mPDF 5.7
MD5: 16c8dbbc47846d95fec95741f17ded0e SHA-1: e3b00066d6d12067f61401e15e8d5ae5ff1749d3 SHA-256: 741d70a16139123ba4dfb37b23b10b2bc1253c7e5b7da8b66ba100abdd439406
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the ML classifier flagged it as malicious, the specific intent appears to be SEO manipulation or directing users to a large collection of other PDFs rather than executing a direct payload. The presence of a 'download button' heuristic further supports a lure-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a07a08a09a01a05/Werner-Forman-s-New-Zealand-by-Werner-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a09a02a03/In-the-Shadow-of-the-Pyramids-Egypt-during-the-Old-Kingdom-by-Werner-Forman.pdf
    • http://muicuiu.dumb1.com/1a01a03a08a07a09a08/Vorfahren-Und-Nachkommen-Der-Adligen-Deutsch-Polnischen-Familie-Werner-Sowie-Deutsche-Und-Polnische-Brger-Und-Adelsfamilien-Im-Lauf-Der-Jahrhunderte-Genealogien-Wappen-Und-Bibliographische-Erschliessungen-Von-Brgerlichen-Und-Adligen-Werner-Familien-by-Werner-Zurek.pdf
    • http://muicuiu.dumb1.com/1a09a01a04a00a06/Just-One-Day-Just-One-Day-1-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/4a03a03a02a05a06/Just-One-Day-Just-One-Day-1-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/4a04a02a05a04a09/I-Was-Here-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/7a07a08a08/I-Have-Lost-My-Way-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/3a03a02a09a06a02/Where-She-Went-If-I-Stay-2-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/7a03a03a03a07a06/J-tais-l-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/8a01a08a05a08/Where-She-Went-If-I-Stay-2-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/5a06a08a02a08a09/J-tais-l-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a09a01a09/My-Life-So-Far-by-Denis-Forman.pdf
    • http://muicuiu.dumb1.com/3a00a01a06a02a01/Better-Angel-by-Forman-Brown.pdf
    • http://muicuiu.dumb1.com/4a05a03a07a07a05/Where-She-Went-If-I-Stay-2-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a08a01a01/Boca-Daze-by-Steven-M-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a08a02a03/Really-Dead-A-Ria-Butler-Mystery-by-J-E-Forman.pdf
    • http://muicuiu.dumb1.com/3a01a04a05a07a02/Sisters-in-Sanity-by-Gayle-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a07a05a02/Turnaround-A-Memoir-by-Milo-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a09a02a08/Becca-s-Story-by-James-D-Forman.pdf
    • http://muicuiu.dumb1.com/6a07a08a08a02a00/Prayers-Like-Shoes-by-Ruth-Forman.pdf