Malicious PDF — malware analysis report

Static analysis result for SHA-256 800a0e6eee16707b…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 08:17:02 +01:00 Authoring application: mPDF 5.7
MD5: 5ce10c1d3cb81a7351482d54b3188fa4 SHA-1: 8aaacda0174a7f2b3e4d2f7986d2e9d9179ab400 SHA-256: 800a0e6eee16707b6db5e546f88e43588abe2d4f701a82560baa6a0823ab8692
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified as a link farm. While the document body is corrupted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious intent to manipulate search engine results or distribute content through a network of linked documents. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a06a09a03a02a02/When-the-Music-Ends-The-Hearts-in-Winter-Chronicles-1-by-Simone-Beaudelaire.pdf
    • http://muicuiu.dumb1.com/1a09a08a04a07a08/When-the-Music-Ends-The-Hearts-in-Winter-Chronicles-1-by-Simone-Beaudelaire.pdf
    • http://muicuiu.dumb1.com/4a07a00a06a01a05/Wonder-Woman-Vol-4-Ends-of-the-Earth-by-Gail-Simone.pdf
    • http://muicuiu.dumb1.com/2a00a01a04a06a04/High-Plains-Promise-Love-on-the-High-Plains-2-by-Simone-Beaudelaire.pdf
    • http://muicuiu.dumb1.com/1a04a06a08a01a03/High-Plains-Holiday-Love-on-the-High-Plains-1-by-Simone-Beaudelaire.pdf
    • http://muicuiu.dumb1.com/6a01a00a00a06a06/Rosetty-Ends-Or-the-Chronicles-of-a-Country-Cobbler-by-A-Dewar-Willock.pdf
    • http://muicuiu.dumb1.com/6a01a00a00a04a03/Rosetty-Ends-Or-the-Chronicles-of-a-Country-Cobbler-by-A-Dewar-Willock.pdf
    • http://muicuiu.dumb1.com/6a01a08a01a03a02/Warm-Hearts-in-Winter-by-Helen-Pollard.pdf
    • http://muicuiu.dumb1.com/1a07a04a00a06a06/Caged-in-Winter-Reluctant-Hearts-1-by-Brighton-Walsh.pdf
    • http://muicuiu.dumb1.com/7a03a01a05a09a03/Baroque-Music-Today-Music-as-Speech-Ways-to-a-New-Understanding-of-Music-by-Nikolaus-Harnoncourt.pdf
    • http://muicuiu.dumb1.com/3a04a05a09a06a06/Paper-Hearts-The-Heartbreaker-Chronicles-2-by-Ali-Novak.pdf
    • http://muicuiu.dumb1.com/1a05a08a07a06a01/Hearts-at-Stake-The-Drake-Chronicles-1-by-Alyxandra-Harvey.pdf
    • http://muicuiu.dumb1.com/1a09a02a03a02a02/Hearts-At-Stake-The-Drake-Chronicles-1-by-Alyxandra-Harvey.pdf
    • http://muicuiu.dumb1.com/2a02a02a02a02a08/Winter-The-Lunar-Chronicles-4-by-Marissa-Meyer.pdf
    • http://muicuiu.dumb1.com/8a05a05a08a09/Winter-The-Lunar-Chronicles-4-by-Marissa-Meyer.pdf
    • http://muicuiu.dumb1.com/6a09a01a05a01/Prince-of-Hearts-The-Elders-and-Welders-Chronicles-1-by-Margaret-Foxe.pdf
    • http://muicuiu.dumb1.com/5a06a08a07a06a00/Thief-of-Hearts-The-Elders-and-Welders-Chronicles-3-by-Margaret-Foxe.pdf
    • http://muicuiu.dumb1.com/1a08a09a00a04a08/Dead-of-Winter-The-Arcana-Chronicles-3-by-Kresley-Cole.pdf
    • http://muicuiu.dumb1.com/1a02a07a04a01a04/The-Dragons-of-Winter-The-Chronicles-of-the-Imaginarium-Geographica-6-by-James-A-Owen.pdf
    • http://muicuiu.dumb1.com/2a07a03a05a01a02/Dragons-of-Winter-Night-Dragonlance-Chronicles-2-by-Margaret-Weis.pdf