Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ae28b1b0aab7c2b…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 05:39:07 +01:00 Authoring application: mPDF 5.7
MD5: 76c3641f716f4db5c8b8afd439cdd577 SHA-1: 9d963362fbac3c7abda35fa5d4d67b1b47b0f1d0 SHA-256: 7ae28b1b0aab7c2b365e562300c628cdc792f0e03e468fa9feb6e1ba02e79209
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which are structured as SEO-friendly slugs, suggesting a link farm designed to redirect users to potentially malicious content. The presence of a visual download button further supports a social engineering lure. While no scripts were explicitly extracted, the PDF structure and link farm heuristic strongly indicate an attempt to trick users into downloading further malicious content, likely via a spearphishing attachment vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a06a02a06a04a08/Nemo-s-Big-Race-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/6a06a02a04a08a03/Nemo-and-the-Surprise-Party-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a00a09a06a09a01/Finding-Nemo-Read-Along-Storybook-and-CD-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/6a06a02a07a04a04/Fish-in-a-Box-Dory-Marlin-Gill-and-Nemo-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/5a00a03a01a04a05/Walt-Disney-s-Christmas-Parade-2-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a00a04a04a06a06/Walt-Disney-s-Worlds-of-Nature-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/3a01a01a05a01a00/Cooking-with-Mickey-Around-our-World-The-Most-Requested-Recipes-from-Walt-Disney-World-and-Disneyland-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/3a04a09a06a05a03/Animation-Walt-Disney-Animation-Studios-The-Archive-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/2a01a05a03a00a02/The-Emperor-s-New-Clothes-Disney-s-wonderful-world-of-reading-29-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a07a00a07a01a03/Fight-to-the-Finish-Disney-Big-Hero-6-Step-into-Reading-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/5a00a03a01a03a08/Winnie-the-Pooh-s-Christmas-Stories-Disney-s-Big-Book-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a04a00a02a08a03/Sleeping-Beauty-Disney-Classic-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/6a07a06a03a06/Robin-Hood-Disney-s-Classic-Storybook-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/8a06a06a01a07a06/Disney-Frozen-Fever-Birthday-Book-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/4a01a06a07a08a05/Beauty-and-the-Beast-Disney-Classic-Series-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a01a04a00a07a03a06/Enten-Im-All-Donaldchens-Mondfahrt-Disney-Enthologien-12-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a00a05a00a09a00a05/Me-Too-Woody-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/7a05a00a02a07/The-Aristocats-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/9a00a07a07a06/Aladdin-by-Walt-Disney-Company.pdf
    • http://muicuiu.dumb1.com/1a00a02a09a00a02/Beauty-and-the-Beast-by-Walt-Disney-Company.pdf