Malicious PDF — malware analysis report

Static analysis result for SHA-256 825d14e38278cd21…

MALICIOUS

PDF

19.1 KB Created: 2019-04-29 23:01:50 +01:00 Authoring application: mPDF 5.7
MD5: 4c5950c7e986765ae810e1568d5a3aed SHA-1: 7918fa1e2c19c8c9d5cb490042d57eef095dadce SHA-256: 825d14e38278cd2134a23905c2618399353c9d85ff1c06270aa26c7f9f7ec4df
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily corrupted, the presence of these links suggests a social engineering attempt to direct users to potentially malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a08a08a07a08a03/The-Mystic-Mirror-Erotic-Fairy-Tale-Romance-by-Sandra-Ross.pdf
    • http://muicuiu.dumb1.com/3a01a08a08a06a08/Ralph-s-Gift-2-Erotic-Romance-by-Sandra-Ross.pdf
    • http://muicuiu.dumb1.com/3a01a08a08a06a07/Ralph-s-Gift-Erotic-Romance-Part-1-by-Sandra-Ross.pdf
    • http://muicuiu.dumb1.com/3a01a08a08a06a06/Playing-the-Not-Dating-Game-Young-Love-Erotic-Romance-by-Sandra-Ross.pdf
    • http://muicuiu.dumb1.com/1a00a00a08a04a09a04/Kirstie-s-Tale---The-Box-Set-A-Tale-of-BDSM-Erotic-Romance-by-Simone-Leigh.pdf
    • http://muicuiu.dumb1.com/6a03a02a04a04a08/Emerald-Mystic-An-After-Hours-Fairy-Tale-by-Lailah-Raziel.pdf
    • http://muicuiu.dumb1.com/9a00a05a09a07/Brute-A-Twisted-Erotic-Fairy-Tale-by-Georgia-Fox.pdf
    • http://muicuiu.dumb1.com/1a02a03a05a08a04/Little-Red-and-the-Big-Bad-Wolf-A-BBW-Paranormal-Erotic-Fairy-Tale-by-Ellen-Dominick.pdf
    • http://muicuiu.dumb1.com/1a02a01a02a06a03/Dominated-in-Wonderland-An-Erotic-Fairy-Tale-by-Ella-Black.pdf
    • http://muicuiu.dumb1.com/1a02a04a02a01a04/The-Princess-and-the-Huntsman-an-erotic-fairy-tale-by-Alexia-Wells.pdf
    • http://muicuiu.dumb1.com/4a01a01a07a08a08/Fairy-Tale-Romance-Collection-Hagenheim-1-5-by-Melanie-Dickerson.pdf
    • http://muicuiu.dumb1.com/2a07a05a04a00a02/Mirror-Mirror-on-the-Wall-Women-Writers-Explore-Their-Favorite-Fairy-Tales-by-Kate-Bernheimer.pdf
    • http://muicuiu.dumb1.com/1a00a08a04a02a07/The-Most-Wonderful-Fairy-Tale-Fairy-Tale-Chronicles-1-by-Nicholas-Jobe.pdf
    • http://muicuiu.dumb1.com/5a06a09a05a02a00/Not-Quite-the-Fairy-Tale-Volume-1-Not-Quite-the-Fairy-Tale-1-4-by-May-Sage.pdf
    • http://muicuiu.dumb1.com/3a06a02a00a00a06/Americana-Fairy-Tale-Fairy-Tales-of-the-Open-Road-1-by-Lex-Chase.pdf
    • http://muicuiu.dumb1.com/1a02a09a09a07a07/Fairy-Tale-as-Myth-Myth-as-Fairy-Tale-by-Jack-D-Zipes.pdf
    • http://muicuiu.dumb1.com/4a00a00a00a07a09/HER-LUST-Bdsmerotica-Romance-Bdsmerotica-Romance-Erotic-Nonconsent-Forced-Sex-and-Rape-Stories-by-Edward-Sherldon.pdf
    • http://muicuiu.dumb1.com/1a00a00a08a04a09a03/A-Dream-of-White-Horses-A-Steamy-Tale-of-Romance-and-the-Meeting-of-Strangers-Kirstie-s-Tale-Book-1-by-Simone-Leigh.pdf
    • http://muicuiu.dumb1.com/4a03a06a06a04a08/The-Mating-Wild-Cats-1-by-Sandra-Ross.pdf
    • http://muicuiu.dumb1.com/3a07a06a04a02a07/Angel-at-Law-I-Earthbound-Angels-2-by-Sandra-Ross.pdf