Malicious PDF — malware analysis report

Static analysis result for SHA-256 81c4b2e448056257…

MALICIOUS

PDF

20.3 KB Created: 2019-04-29 23:28:56 +01:00 Authoring application: mPDF 5.7
MD5: 2dd93f280e0eeddd5d3a38756ff7f001 SHA-1: 52355a24be6f52267b47f8ac9ff1e3a97d9d66c0 SHA-256: 81c4b2e44805625744a3b7192995e68ecf53207de29ef1878770b40f483f09de
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While the document body is heavily obfuscated, the heuristic firings strongly indicate a malicious intent, likely related to distributing further payloads or engaging in link farming. No scripts were extracted, but the presence of numerous external links suggests a potential for downloading additional malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a03a03a06a07a09/The-Barrier-Between-Collector-2-by-Stacey-Marie-Brown.pdf
    • http://muicuiu.dumb1.com/2a05a07a07a07a07/Beast-in-the-Darkness-Darkness-2-5-by-Stacey-Marie-Brown.pdf
    • http://muicuiu.dumb1.com/1a03a04a01a04a03/Fire-in-the-Darkness-Darkness-2-by-Stacey-Marie-Brown.pdf
    • http://muicuiu.dumb1.com/1a03a02a07a07a06/Darkness-of-Light-Darkness-1-by-Stacey-Marie-Brown.pdf
    • http://muicuiu.dumb1.com/6a09a02a05a06a04/The-Collector-The-Bone-Collector-2-by-Fiona-Cummins.pdf
    • http://muicuiu.dumb1.com/2a01a04a01a01a08/The-Sin-Collector-The-Sin-Collector-1-by-Jessica-Fortunato.pdf
    • http://muicuiu.dumb1.com/1a02a09a07a01a03/Song-of-the-Vikings-Snorri-and-the-Making-of-Norse-Myths-by-Nancy-Marie-Brown.pdf
    • http://muicuiu.dumb1.com/4a05a01a05a02a03/Debt-Collector-Season-One-Debt-Collector-1-9-by-Susan-Kaye-Quinn.pdf
    • http://muicuiu.dumb1.com/2a03a09a07a06/Barrier-by-Brian-K-Vaughan.pdf
    • http://muicuiu.dumb1.com/5a07a09a02a08a05/The-Barrier-La-Barri-re-by-Ren-Bazin.pdf
    • http://muicuiu.dumb1.com/2a02a01a04a07a02/Across-the-Great-Barrier-by-Patricia-C-Wrede.pdf
    • http://muicuiu.dumb1.com/2a01a05a00a02a06/The-Santaroga-Barrier-by-Frank-Herbert.pdf
    • http://muicuiu.dumb1.com/9a01a01a02a00a02/The-Blood-Brain-Barrier-BBB-by-Gert-Fricker.pdf
    • http://muicuiu.dumb1.com/9a01a01a02a05a08/The-Blood-Brain-Barrier-by-Gert-Fricker.pdf
    • http://muicuiu.dumb1.com/9a08a07a07a01a01/Zeit-Und-Zeiterfahrung-in-Der-Deutschsprachigen-Lyrik-Der-Fuenfziger-Jahre-Marie-Luise-Kaschnitz-Ingeborg-Bachmann-Und-Christine-Lavant-by-Cordula-Drossel-Brown.pdf
    • http://muicuiu.dumb1.com/3a00a06a05a08a05/Through-the-Barrier-Princes-and-Priests-1-Novels-of-Shannon-1-by-Angela-MacDonald.pdf
    • http://muicuiu.dumb1.com/6a02a02a08a05a09/Comic-Book-Dirty-Brown-A-successful-young-African-American-female-DJ-losses-her-power-to-entertain-her-fans-DJ-Dirty-Brown-Book-1-by-Tammy-Brown-Elkeles.pdf
    • http://muicuiu.dumb1.com/5a04a06a00a08a04/The-Conversion-of-Marie-Alphonse-Ratisbonne-1842-by-Marie-Th-odore-Renouard-De-Bussierre.pdf
    • http://muicuiu.dumb1.com/1a01a08a03a06a09a04/Das-Triptychon-Von-Marie-Redonnet-ALS-Kritische-Gesellschaftsstudie-in-Der-Franzosischen-Gegenwartsliteratur-by-Marie-Mader.pdf
    • http://muicuiu.dumb1.com/8a03a02a05a08a00/Le-Milieu-Familial-de-Marie-Guyard-Marie-de-L-Incarnation-1599-1672-by-Jacques-Amirault.pdf