Malicious PDF — malware analysis report

Static analysis result for SHA-256 7bfc125b01f3ed00…

MALICIOUS

PDF

18.4 KB Created: 2019-04-30 08:54:07 +01:00 Authoring application: mPDF 5.7
MD5: 69562ab92c9e622a06a31fd296de5d42 SHA-1: 4ce4477b5828b5456c03f154bfe651b5bf150b5e SHA-256: 7bfc125b01f3ed00b8bba5aaad7cd353b3514518d390c38643031b49f48617cf
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links disguised as book downloads, forming a link farm. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to redirect users to potentially harmful sites. The presence of a 'SE_DOWNLOAD_BUTTON' heuristic further suggests a deceptive user interface.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a02a06a07a02/Brian-Wilson-amp-the-Beach-Boys-How-Deep-Is-the-Ocean-by-Paul-Williams.pdf
    • http://muicuiu.dumb1.com/4a09a00a06a08a00/The-Deep-End-of-the-Ocean-by-Jacquelyn-Mitchard.pdf
    • http://muicuiu.dumb1.com/8a07a02a03a09a01/The-Glass-Ocean-the-Glass-Ocean-A-Novel-a-Novel-by-Beatriz-Williams.pdf
    • http://muicuiu.dumb1.com/6a09a09a06a09a09/How-Deep-Is-the-Ocean-by-Kathleen-Weidner-Zoehfeld.pdf
    • http://muicuiu.dumb1.com/1a04a03a04a00a01/Journey-Into-the-Deep-Discovering-New-Ocean-Creatures-by-Rebecca-L-Johnson.pdf
    • http://muicuiu.dumb1.com/1a00a02a02a03a03a08/The-Deep-End-of-the-Ocean-by-Jacquelyn-Mitchard-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://muicuiu.dumb1.com/1a02a06a06a06a08/National-Geographic-Atlas-of-the-Ocean-The-Deep-Frontier-by-Sylvia-A-Earle.pdf
    • http://muicuiu.dumb1.com/2a07a07a04a07/Bats-at-the-Beach-by-Brian-Lies.pdf
    • http://muicuiu.dumb1.com/1a01a07a01a00a01a00/Henderson-s-Boys-Robert-Muchamore-Paul-Clarke-Marc-Kilgour-List-of-Henderson-s-Boys-Characters-by-Books-LLC.pdf
    • http://muicuiu.dumb1.com/4a04a01a08a08a00/On-Some-Faraway-Beach-The-Life-and-Times-of-Brian-Eno-by-David-Sheppard.pdf
    • http://muicuiu.dumb1.com/5a02a07a03/The-Night-Ocean-by-Paul-La-Farge.pdf
    • http://muicuiu.dumb1.com/4a00a01a08a01a05/Empire-of-the-Deep-The-Rise-and-Fall-of-the-British-Navy-by-Ben-Wilson.pdf
    • http://muicuiu.dumb1.com/9a09a00a03a02a06/Return-Of-The-Deep-Ones-And-Other-Mythos-Tales-by-Brian-Lumley.pdf
    • http://muicuiu.dumb1.com/8a01a02a09a01/Never-Goodbye-Albany-Boys-1-by-Kerri-Williams.pdf
    • http://muicuiu.dumb1.com/3a06a08a08a08a01/Honeymoon-on-the-Moon-by-Brian-Wilson.pdf
    • http://muicuiu.dumb1.com/9a01a05a04a05/Brothers-in-Hope-The-Story-of-the-Lost-Boys-of-Sudan-by-Mary-Williams.pdf
    • http://muicuiu.dumb1.com/5a02a07a07a06a04/Kingfisher-Encyclopedia-Of-Questions-And-Answers-by-Brian-Williams.pdf
    • http://muicuiu.dumb1.com/9a07a06a07a02/The-Seacrest-Paines-Creek-Beach-1-by-Aaron-Paul-Lazar.pdf
    • http://muicuiu.dumb1.com/1a00a02a02a02a09a05/Novels-by-Jacquelyn-Mitchard-The-Deep-End-of-the-Ocean-A-Theory-of-Relativity-Cage-of-Stars-by-Jacquelyn-Mitchard.pdf
    • http://muicuiu.dumb1.com/5a05a04a02a02a01/Against-Their-Wills-A-Diabolic-White-Slavery-Ring-Is-Hunted-Down-by-Brian-H-Williams.pdf