Malicious PDF — malware analysis report

Static analysis result for SHA-256 79f91bb45b756410…

MALICIOUS

PDF

24.5 KB Created: 2019-04-30 06:28:45 +01:00 Authoring application: mPDF 5.7
MD5: f0addb7beb5b7274a288f38d305dd2fd SHA-1: 51d900f00055cd84c04ded6af05ad64c0b12cc53 SHA-256: 79f91bb45b756410f2ad69544f217ed4f5f5ec8bd2261241f9657b93a507d453
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious sites. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/5a04a06a04a03a08/Egypt-Land-of-the-Pharaohs-by-Regine-Schulz.pdf
    • http://muicuiu.dumb1.com/5a00a02a04a04a00/Egypt-Land-of-the-Pharaohs-by-Dale-Brown.pdf
    • http://muicuiu.dumb1.com/4a00a03a04a00a02/Red-Land-Black-Land-Daily-Life-in-Ancient-Egypt-by-Barbara-Mertz.pdf
    • http://muicuiu.dumb1.com/4a07a04a00a01a02/Incidents-of-Travel-in-Egypt-Arabia-Petraea-amp-the-Holy-Land-by-John-Lloyd-Stephens.pdf
    • http://muicuiu.dumb1.com/6a00a05a08a03a07/Explorations-in-Bible-Land-During-the-19th-Century-Vol-2-Palestine-Egypt-Arabia-and-Hittite-Areas-by-H-V-Hilprecht.pdf
    • http://muicuiu.dumb1.com/7a05a02a05a06a06/The-Treasures-of-Ancient-Egypt-From-the-Rosetta-Stone-to-the-Tomb-of-Tutankhamun---The-Search-for-the-Riches-of-Ancient-Egypt-by-Jaromir-Malek.pdf
    • http://muicuiu.dumb1.com/8a09a07a01a03a06/Egypt-in-Search-of-Political-Community-An-Analysis-of-the-Intellectual-and-Political-Evolution-of-Egypt-1804-1952-by-Nadav-Safran.pdf
    • http://muicuiu.dumb1.com/8a07a01a08a06a01/Charlie-Brown-and-Charles-Schulz-by-Charles-M-Schulz.pdf
    • http://muicuiu.dumb1.com/8a07a01a04a07a09/Letters-and-Drawings-of-Bruno-Schulz-by-Bruno-Schulz.pdf
    • http://muicuiu.dumb1.com/1a07a06a05a06a02/Imprisoned-with-the-Pharaohs-by-H-P-Lovecraft.pdf
    • http://muicuiu.dumb1.com/5a06a08a00a02a08/African-Philosophy-During-The-Period-Of-The-Pharaohs-2800-330-B-C-by-Theophile-Obenga.pdf
    • http://muicuiu.dumb1.com/1a00a04a05a03a07/Why-the-Pharaohs-Built-the-Pyramids-with-Fake-Stones-by-Joseph-Davidovits.pdf
    • http://muicuiu.dumb1.com/1a00a01a07a07a04a00/Propagandisten-Der-Grosstadt-Die-Bedeutung-Von-Informationsstroemen-Zwischen-Stadt-Und-Land-Bei-Der-Ausloesung-Neuzeitlicher-Land-Stadt-Wanderungen-Illustriert-an-Beispielen-Aus-Dem-Hohenloher-Land-Baden-Wuerttemberg-Und-Den-Benachbarten-Zentren-Fr-by-Wolfgang-Kromer.pdf
    • http://muicuiu.dumb1.com/8a02a09a00a09a09/The-Pharaohs-Code-Creating-a-Joyful-Life-and-a-Lasting-Legacy-by-Mohamed-Tohami.pdf
    • http://muicuiu.dumb1.com/5a00a02a04a03a08/Private-Lives-of-the-Pharaohs-Unlocking-the-Secrets-of-Egyptian-Royalty-by-Joyce-A-Tyldesley.pdf
    • http://muicuiu.dumb1.com/4a03a07a03a05a09/The-World-of-the-Pharaohs-A-Complete-Guide-to-Ancient-Eqypt-by-Christine-Hobson-el-Mahdy.pdf
    • http://muicuiu.dumb1.com/9a02a00a00a06a07/The-Curse-of-the-Pharaohs-A-Stunning-Investigation-Into-the-4-000-Year-Old-Secrets-of-the-Ancient-Egyptians-by-Philipp-Vandenberg.pdf
    • http://muicuiu.dumb1.com/7a00a05a09a03a01/The-Crusades-by-R-gine-Pernoud.pdf
    • http://muicuiu.dumb1.com/8a00a02a05a05a06/Attirance-by-Regine-Franceschi.pdf
    • http://muicuiu.dumb1.com/7a00a05a09a02a00/A-Day-With-A-Noblewoman-by-R-gine-Pernoud.pdf