Malicious PDF — malware analysis report

Static analysis result for SHA-256 847363350392921d…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 07:45:02 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-04
MD5: 82572e774b59ad6bf03e822263fdc412 SHA-1: 5c9e1677aec9b98e10ff1396368861a7d88c52b8 SHA-256: 847363350392921d48aae49a18c82b633bd4cc1900ae90abf4feeff2d79e27c4
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. The SE_DOWNLOAD_BUTTON heuristic indicates a potential call-to-action, reinforcing the lure. The extracted URLs, although marked as benign, are part of the link farm, and the overall structure points to a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a03a09a06a06a06/The-Cocktail-Party-by-T-S-Eliot.pdf In PDF document text
    • http://muicuiu.dumb1.com/1a00a08a05a01a03a01/Cocktail-Party-A-Gangbang-Orgy-Short-by-Geena-Flix.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a05a09a08a06a09/Mental-Floss-Cocktail-Party-Cheat-Sheets-by-Mangesh-Hattikudur.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a09a05a02a00a05/What-to-Talk-About-On-a-Plane-at-a-Cocktail-Party-in-a-Tiny-Elevator-with-Your-Boss-s-Boss-by-Chris-Colin.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a08a01a00a04a08/Eliot-and-His-Age-T-S-Eliot-s-Moral-Imagination-in-the-Twentieth-Century-by-Russell-Kirk.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a05a00a07a00a00/Old-Possum-s-Book-of-Practical-Cats-by-T-S-Eliot-by-T-S-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a07a08a07a09/T-S-Eliot-Reads-The-Wasteland-Four-Quartets-and-Other-Poems-by-T-S-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a01a08a08a09/Letters-of-T-S-Eliot-1898-1922-by-T-S-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a05a09a09a04a05/George-Eliot-Adam-Bede-The-Mill-on-the-Floss-Silas-Marner-Middlemarch-by-George-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a09a01a03a07a09/Polly-the-Party-Fun-Fairy-Rainbow-Magic-19-Party-Fairies-5-by-Daisy-Meadows.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a01a03a09a05a09/Forking-Fantastic-Put-the-Party-Back-in-Dinner-Party-by-Zora-O-39-Neill.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a08a08a01a01a02/Middlemarch-By-George-Eliot---Illustrated-And-Unabridged-by-George-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a09a00a03a03a03/Let-s-Party-How-to-Succeed-in-Party-Plan-by-Jan-Ruhe.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a09a05a08a06/Middlemarch-Novel-1871-by-George-Eliot-Pen-Name-of-Mary-Ann-Evans-It-Was-First-Published-in-1871-to-1872-by-George-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a00a01a00a09/The-Poetry-of-T-S-Eliot-by-T-S-Eliot.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a01a06a09a03a04/The-Cocktail-Bar-by-Isabella-May.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a02a00a03a09a04/Mai-Tai-d-Up-Cocktail-4-by-Alice-Clayton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a04a01a08a02/Mai-Tai-d-Up-Cocktail-4-by-Alice-Clayton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a09a05a09a06a09/Horror-Cocktail-by-Anja-Bahle.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a05a09a04a06/Screwdrivered-Cocktail-3-by-Alice-Clayton.pdfIn PDF document text