Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6e4d0d83a83bba3…

MALICIOUS

PDF

15.1 KB Created: 2019-05-07 04:40:49 +01:00 Authoring application: mPDF 5.7 First seen: 2021-08-25
MD5: 78fd42e72723d6a1080b662775d910b1 SHA-1: b3773e2198983b64068427e72d60dda645f9e823 SHA-256: b6e4d0d83a83bba39617c82f78c8beb5dbdcd6489568e687d484ec49fb54d7ab
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, many of which are structured to appear as book titles, suggesting a link farm or a lure for users to download potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence. The presence of a 'download button' heuristic further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/2a00a08a08a08a06/Towers-of-Midnight-Wheel-of-Time-13-A-Memory-of-Light-2-by-Robert-Jordan.pdf In PDF document text
    • http://muicuiu.dumb1.com/3a07a07a04a06a09/A-Memory-Of-Light-Wheel-of-Time-14-A-Memory-of-Light-3-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a03a06a08/A-Memory-of-Light-Wheel-of-Time-14-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a00a03a07a09a01/A-Memory-of-Light-Wheel-of-Time-Book-14-Audible-Unabridged-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a07a07a05/The-Wheel-of-time-series-by-Robert-Jordan-1-11-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a06a02a04a08a00/The-Wheel-of-Time-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a02a09a04a07/New-Spring-Wheel-of-Time-0-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a04a07a05/New-Spring-Wheel-of-Time-0-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a09a01a06/The-Dragon-Reborn-Wheel-of-Time-3-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a03a03a05a06a08/Vzpom-nka-na-Sv-tlo-Wheel-of-Time-14-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a08a04a08a04/The-Path-of-Daggers-Wheel-of-Time-8-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a07a09a05/The-Path-of-Daggers-Wheel-of-Time-8-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a08a05a05a09a00/Un-Lever-de-T-n-bres-Wheel-of-Time-4-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a01a06a04a05/The-Shadow-Rising-Wheel-of-Time-4-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a04a05a01a07/Crossroads-of-Twilight-Wheel-of-Time-10-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a00a04a00/The-Shadow-Rising-Wheel-of-Time-4-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a03a05a04a01/The-Fires-of-Heaven-Wheel-of-Time-5-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a07a02a00a08/Winter-s-Heart-Wheel-of-Time-9-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a01a06a04a03/The-Dragon-Reborn-Wheel-of-Time-3-by-Robert-Jordan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a03a00a09a00/The-Wheel-of-Time-Collection-1-12-First-12-volume-s-of-the-series-by-Robert-Jordan.pdfIn PDF document text