Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc7369f953f3cf24…

MALICIOUS

PDF

26.1 KB Created: 2019-05-07 09:23:11 +01:00 Authoring application: mPDF 5.7 First seen: 2021-11-21
MD5: 949e09de88f6c3c9ecd8f1f628b0d631 SHA-1: 916bb188e806172873ed88ccf9f4f459b5821dd9 SHA-256: bc7369f953f3cf24402420a9322b795ecb1f5d2657d612483ea9b8ad7eb63a58
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common technique for distributing malicious content. The ML classifier also strongly indicated maliciousness. While no scripts were directly extracted, the PDF structure and the presence of numerous external links suggest an attempt to redirect the user to a malicious site, likely for further exploitation or malware download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/4a00a03a04a00a02/Red-Land-Black-Land-Daily-Life-in-Ancient-Egypt-by-Barbara-Mertz.pdf In PDF document text
    • http://muicuiu.dumb1.com/7a05a02a05a06a06/The-Treasures-of-Ancient-Egypt-From-the-Rosetta-Stone-to-the-Tomb-of-Tutankhamun---The-Search-for-the-Riches-of-Ancient-Egypt-by-Jaromir-Malek.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a01a07a07a04a00/Propagandisten-Der-Grosstadt-Die-Bedeutung-Von-Informationsstroemen-Zwischen-Stadt-Und-Land-Bei-Der-Ausloesung-Neuzeitlicher-Land-Stadt-Wanderungen-Illustriert-an-Beispielen-Aus-Dem-Hohenloher-Land-Baden-Wuerttemberg-Und-Den-Benachbarten-Zentren-Fr-by-Wolfgang-Kromer.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a00a02a04a04a00/Egypt-Land-of-the-Pharaohs-by-Dale-Brown.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a04a06a04a03a08/Egypt-Land-of-the-Pharaohs-by-Regine-Schulz.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a07a04a00a01a02/Incidents-of-Travel-in-Egypt-Arabia-Petraea-amp-the-Holy-Land-by-John-Lloyd-Stephens.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a00a05a08a03a07/Explorations-in-Bible-Land-During-the-19th-Century-Vol-2-Palestine-Egypt-Arabia-and-Hittite-Areas-by-H-V-Hilprecht.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a05a04a05a03a09/Land-of-Hidden-Fires-Lynde-Eldars-Land-by-Tarjei-Vesaas.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a04a04a05a06/Land-of-Savagery-Land-of-Promise-The-European-Image-of-the-American-Frontier-by-Ray-Allen-Billington.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a02a04a06a09/Land-of-the-Rainbow-Snake-Aboriginal-Children-s-Stories-and-Songs-from-Western-Arnhem-Land-by-Catherine-H-Berndt.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a02a09a06a02/Land-That-Moves-Land-That-Stands-Still-by-Kent-Nelson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a09a00a08a06a01/Daily-Life-in-Ancient-India-From-200-BC-to-700-AD-by-Jeannine-Auboyer.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a09a03a04a05a00/Custom-Land-and-Livelihood-in-Rural-South-China-The-Traditional-Land-Law-of-Hong-Kong-s-New-Territories-1750-1950-by-Patrick-Hase.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a06a07a04a04a01/Land-of-Nod-The-Prophet-Land-of-Nod-2-by-Gary-Hoover.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a07a05a00a01/Land-of-Nod-The-Artifact-Land-of-Nod-1-by-Gary-Hoover.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a06a07a03a07a06/Land-of-Nod-The-Artifact-Land-of-Nod-1-by-Gary-Hoover.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a08a00a09a00a06/Im-Land-des-Fl-sterns-Geschichten-aus-dem-Alltag-in-Nordkorea-by-Barbara-Demick.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a09a03a05a04/Daily-Life-in-Ancient-Rome-The-People-and-the-City-at-the-Height-of-the-Empire-by-J-r-me-Carcopino.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a03a02a09a07/Land-of-Black-Gold-Tintin-15-by-Herg-.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a06a06a01a05a07/We-Wanted-a-Farm-A-Back-to-the-Land-Adventure-from-1941-Back-to-the-Land-Adventures-Book-2-by-M-G-Kains.pdfIn PDF document text