Malicious PDF — malware analysis report

Static analysis result for SHA-256 77e640fbe69a06dd…

MALICIOUS

PDF

23.8 KB Created: 2019-04-30 04:32:52 +01:00 Authoring application: mPDF 5.7
MD5: 64a563c29f9494fd0d81b991f84fb3ab SHA-1: a89983b29d8da2f9ac4b908df38c341715c78ed1 SHA-256: 77e640fbe69a06ddba918b0ef9528db2a0a4363cc60a942b54a118f5b2ada515
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links are marked as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS firing suggest a malicious intent, possibly to drive traffic or distribute further malicious content. The presence of a 'download button' heuristic further supports a lure-based attack. No scripts were extracted, but the embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a06a03a03a05a00/Orden-de-las-Estrellas-Cruzados-de-las-estrellas-n-1-by-Alan-Somoza.pdf
    • http://muicuiu.dumb1.com/7a06a03a03a05a04/Orden-del-Acero-Cruzados-de-las-estrellas-n-2-by-Alan-Somoza.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a07a05/Nicaraguan-Revolution-Anastasio-Somoza-Debayle-Sandinista-National-Liberation-Front-Daniel-Ortega-National-Guard-Anastasio-Somoza-Garc-a-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a06a05/Out-of-This-World-Poems-by-Joseph-Somoza.pdf
    • http://muicuiu.dumb1.com/1a00a05a07a09a07a03/The-Twelve-Days-of-Christmas-Ideas-for-a-More-Meaningful-Holiday-Season-by-Betty-Van-Orden.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a02a03/El-exorcismo-de-la-ni-a-Somoza-by-Amaro-Borja.pdf
    • http://muicuiu.dumb1.com/1a00a09a05a08a05a05/Der-Anteil-Des-Kardinals-Ugolino-an-Der-Ausbildung-Der-Drei-Orden-Des-Heiligen-Franz-by-Lilly-Zarncke.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a08a01/Somoza-s-Last-Stand-Testimonies-from-Nicaragua-by-Larry-Towell.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a02a04/The-Krogan-s-Nest-In-Strange-Orbits-3-by-Ramon-Somoza.pdf
    • http://muicuiu.dumb1.com/1a00a07a00a09a06a01/Romantic-Thriller-Doppelband-6-Der-Orden-der-Maske-Irgendwann-in-einem-anderen-Leben-by-Alfred-Bekker.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a02a07/The-Regime-of-Anastasio-Somoza-1936-1956-by-Knut-Walter.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a08a00/Dictators-Never-Die-A-Portrait-Of-Nicaragua-And-The-Somoza-Dynasty-by-Eduardo-Crawley.pdf
    • http://muicuiu.dumb1.com/7a06a03a02a03a03/The-United-States-and-Somoza-1933-1956-A-Revisionist-Look-by-Paul-Coe-Clark.pdf
    • http://muicuiu.dumb1.com/1a01a08a04a00a00a06/La-felicidad-despu-s-del-orden-Una-clase-magistral-ilustrada-sobre-el-arte-de-organizar-el-hogar-y-la-vida-by-Marie-Kond-.pdf
    • http://muicuiu.dumb1.com/3a09a02a02a04a04/Alan-Watts-Teaches-Meditation-by-Alan-W-Watts.pdf
    • http://muicuiu.dumb1.com/7a06a03a03a00a03/The-Man-with-Kaleidoscope-Eyes-The-Art-of-Alan-Aldridge-by-Alan-Aldridge.pdf
    • http://muicuiu.dumb1.com/1a01a06a04a07a09a07/Tamora-Pierce---Knights-of-Tortall-Acton-of-Fenrigh-Alan-of-Pirate-s-Swoop-Alan-of-Trebond-Alanna-of-Pirate-s-Swoop-and-Olau-Alexander-of-Tirragen-Anders-of-Mindelan-Balduin-of-Disart-Cleon-of-Kennan-Conal-of-Mindelan-by-Source-Wikia.pdf
    • http://muicuiu.dumb1.com/1a02a09a05a03a04/Alan-Moore-s-The-Courtyard-by-Alan-Moore.pdf
    • http://muicuiu.dumb1.com/1a03a02a06a06a09/This-Boy-by-Alan-Johnson.pdf
    • http://muicuiu.dumb1.com/1a04a03a00a05a01/Top-10-Vol-1-by-Alan-Moore.pdf