Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8c158ebb87606c7…

MALICIOUS

PDF

19.3 KB Created: 2019-04-29 23:14:54 +01:00 Authoring application: mPDF 5.7 First seen: 2021-10-12
MD5: ac281e7ef489a889da58f54682067418 SHA-1: eb4b51620105285ef9075f4a63d327ed66516b2b SHA-256: b8c158ebb87606c78bfe8a08675abee03d23d353e0b6686dc2bf2a16e435a3f6
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm with 26 external links, many of which point to PDF files with book titles. This heuristic, combined with the ML classifier's high confidence, suggests a malicious intent to redirect users to potentially harmful content. The presence of a 'download button' lure further supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/7a01a08a05a05/Green-Calder-Grass-Calder-Saga-6-by-Janet-Dailey.pdf In PDF document text
    • http://muicuiu.dumb1.com/4a09a03a09a00a04/Calder-Born-Calder-Bred-Calder-Saga-4-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a08a07a03a05a02/This-Calder-Sky-Calder-Saga-3-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a01a03a09a07/Adverse-Report-Keith-Calder-12-by-Gerald-Hammond.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a08a09a06a02/The-Untold-Story-My-20-Years-Running-the-National-Inquirer-by-Iain-Calder.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a08a04a07a09/Sources-and-Analogues-of-Old-English-Poetry-The-Major-Latin-Texts-in-Translation-by-Daniel-G-Calder.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a00a02a00a03a02/Empire-of-Secrets-British-Intelligence-the-Cold-War-and-the-Twilight-of-Empire-by-Calder-Walton.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a00a07a08a02/Revolutionary-Empire-The-Rise-of-the-English-Speaking-Empire-from-the-Fifteenth-Century-to-the-1780s-by-Angus-Calder.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a06a01a08a00a02/How-to-Read-a-Nautical-Chart-A-Complete-Guide-to-the-Symbols-Abbreviations-and-Data-Displayed-on-Nautical-Charts-by-Nigel-Calder.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a09a04a07a07/Aspen-Gold-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a06a01a05a07/A-Capital-Holiday-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a07a09a06a03a03/Honor-Bannon-Brothers-2-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a09a08a06a05/Fire-and-Ice-California-Americana-5-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a03a01a05a08/A-Land-Called-Deseret-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a09a01a04a03a02/Silver-Wings-Santiago-Blue-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a00a04a02a00/Separate-Cabins-Silhouette-Romance-213-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a06a01a08a01/Summer-Mahogany-Maine-Americana-19-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a03a00a04a07/Fiesta-San-Antonio-Cord-amp-Stacy-2-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a04a03a01a08/Santa-s-Little-Helpers-The-Healing-Touch-Twelfth-Night-Comfort-and-Joy-by-Janet-Dailey.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a04a05a02a04a01/Texas-Free-The-Tylers-of-Texas-5-by-Janet-Dailey.pdfIn PDF document text