Malicious PDF — malware analysis report

Static analysis result for SHA-256 8365b109bd759ee5…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 03:24:18 +01:00 Authoring application: mPDF 5.7 First seen: 2020-07-24
MD5: 0a4990fce62e38fb86bd4cbd5a9ba249 SHA-1: 64bed8f6f5604b4145bd223318519f5138ecdb78 SHA-256: 8365b109bd759ee5903e27d49653fece345ac3bd39a1cad8b015630b299e1f2c
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the document body is unreadable, the heuristic firings suggest a malicious intent to direct users to external content. The presence of a visual download button lure further supports this, though the exact payload or purpose beyond link distribution is unclear. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a04a03a06a07a08/The-Devil-is-in-the-Details-Examining-Matt-Murdock-and-Daredevil-by-Ryan-K-Lindsay.pdf In PDF document text
    • http://muicuiu.dumb1.com/1a01a06a09a01a07a06/Daredevil-Volume-4-The-Autobiography-of-Matt-Murdock-by-Mark-Waid.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a09a00a02a08/Daredevil-Volume-1-Devil-at-Bay-by-Mark-Waid.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a04a01a03a08a07/Daredevil-Vol-1-Guardian-Devil-by-Kevin-Smith.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a02a09a00a02a03/Devil-in-the-Details-by-Tracy-Rowan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a00a09a06a05a01/Missing-411-The-Devil-s-in-the-Details-by-David-Paulides.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a06a09a01a07a07/The-Book-of-Murdock-Page-Murdock-US-Deputy-Marshal-8-by-Loren-D-Estleman.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a08a03a09a06/The-Devil-s-Details-A-History-of-Footnotes-by-Chuck-Zerby.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a00a09a06a04a08/Details-Magazine-November-2009-by-Details.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a01a09a05a02/Details-of-the-Hunt-Details-1-by-Laura-Baumbach.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a09a00a01a02a07/The-Increment-Matt-Browning-2-by-Chris-Ryan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a09a00a01a02a05/Greed-Matt-Browning-1-by-Chris-Ryan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a09a03a04a07a08/Grendel-Devil-by-the-Deed-by-Matt-Wagner.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a00a08a06a03a04/The-Devil-s-Fire-Devil-s-Fire-1-by-Matt-Tomerlin.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a05a07a08a09/The-Devil-s-Handshake-A-Basil-and-Moebius-Adventure-by-Ryan-Schifrin.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a06a05a00a07/Declarations-of-Independence-Cross-Examining-American-Ideology-by-Howard-Zinn.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a01a08a03a01a01/Examining-Tuskegee-The-Infamous-Syphilis-Study-and-Its-Legacy-by-Susan-M-Reverby.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a03a07a02a04a00/Derivatives-in-Islamic-Finance-Examining-the-Market-Risk-Management-Framework-by-Sherif-Ayoub.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a07a01a05a00/End-of-the-Civil-War-by-E-E-Doc-Murdock.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a06a05a03a02a04/Peasant-Agriculture-and-Share-Tenancy-in-Orissa-Examining-Neoclassical-and-Marxist-Approach-by-Mamata-Swain.pdfIn PDF document text