Malicious PDF — malware analysis report

Static analysis result for SHA-256 b074f628b4b74351…

MALICIOUS

PDF

19.5 KB Created: 2019-05-07 08:28:55 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-20
MD5: c24fe64df82d4c934e956c6997093dc7 SHA-1: 63267ccdd5048e1650138e38c5dec1949c81248e SHA-256: b074f628b4b743512c205e1679fc5f80dda93c75df679cc4cb9458889057ce86
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to other PDF files, suggesting a link farm or a method to distribute malicious content. The ML classifier also flagged this PDF as malicious. The presence of a 'download' button heuristic further supports the idea that the document is designed to trick users into downloading files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/3a04a05a06a03a01/A-Cold-Creek-Secret-Cowboys-of-Cold-Creek-7-by-RaeAnne-Thayne.pdf In PDF document text
    • http://muicuiu.dumb1.com/1a01a06a02a09/A-Cold-Creek-Noel-Cowboys-of-Cold-Creek-11-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a05a03a07/The-Pines-of-Winder-Ranch-A-Cold-Creek-Homecoming-A-Cold-Creek-Reunion-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a02a01a04a04/Dancing-In-The-Moonlight-Cowboys-of-Cold-Creek-2-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a02a08a06a09/Murder-At-Cold-Creek-College-Cold-Creek-1-by-Christa-Nardi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a05a06a04a09/The-Cowboys-of-Chance-Creek-Books-1-3-The-Cowboys-of-Chance-Creek-1-3-by-Cora-Seton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a05a00a07a09a04/Le-rempart-du-mensonge---Nuit-d-hiver-Cold-Creek-Le-d-fi-des-Hollister-t-4-by-Beverly-Long.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a04a02a08a00/A-Cadence-Creek-Christmas-Cadence-Creek-Cowboys-5-by-Donna-Alward.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a03a03a08a07a03/The-Maverick-of-Copper-Creek-Copper-Creek-Cowboys-1-by-R-C-Ryan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a09a03a09a00a07/Holiday-in-Stone-Creek-A-Stone-Creek-Christmas-At-Home-in-Stone-Creek-Stone-Creek-4-amp-6-by-Linda-Lael-Miller.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a00a02a07a03a07/Blackberry-Summer-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a03a08a04a02a09/The-Cowboy-Inherits-a-Bride-The-Cowboys-of-Chance-Creek-0-5-by-Cora-Seton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a02a05a01a03a01/Season-of-Wonder-Haven-Point-9-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a09a03a06/High-Risk-Affair-by-RaeAnne-Thayne.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a07a08a06a06a01/The-Cold-Cold-Ground-Detective-Sean-Duffy-1-by-Adrian-McKinty.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a02a01a08a06a00/A-Cold-Day-in-Hell-Cold-Case-Investigation-1-by-Lissa-Marie-Redmond.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a03a06a08/A-Cold-Dark-Place-Cold-Justice-1-by-Toni-Anderson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a01a07a08a01a05/Over-in-the-Arctic-Where-the-Cold-Winds-Blow-Where-the-Cold-Wind-Blows-Sharing-Nature-with-Children-Books-by-Marianne-Berkes.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a06a01a06a04/Cold-Secrets-Cold-Justice-7-by-Toni-Anderson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a09a04a05a06a08/Cold-Blooded-Cold-Justice-9-by-Toni-Anderson.pdfIn PDF document text