Malicious PDF — malware analysis report

Static analysis result for SHA-256 bee0eecb464d7101…

MALICIOUS

PDF

16.9 KB Created: 2019-04-29 23:29:00 +01:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: 43ff420042c3293a154e7cc4179b4b6b SHA-1: a9f728b8e2be2d9b7762518f6d966aaf894fe2c4 SHA-256: bee0eecb464d71016ef7cdd9d7b84e7aa184567a43e4ea2bff7b14d3ceab7054
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, masquerading as book titles, which is indicative of a link farm designed to trick users into downloading malicious content. The ML classifier also flagged this PDF with high confidence. The presence of a 'download button' heuristic further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a03a02a08a08a09/Seven-Days-From-Sunday-MP-5-CIA-Thriller-1-by-M-H-Sargent.pdf In PDF document text
    • http://muicuiu.dumb1.com/4a09a09a06a00a08/7-Days-and-Seven-Nights-A-Thriller-by-Melinda-Michelle.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a09a05a00a04a04/Two-Days-in-Caracas-Titus-Ray-Thriller-2-by-Luana-Ehrlich.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a03a03a05a03/At-Bay-Redemption-Thriller-1-Alex-Troutt-Thriller-1-by-John-W-Mefford.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a05a02a00a07a07/Thriller-Writing-A-creative-writing-and-self-publishing-guide-for-aspiring-thriller-novelists-by-Ash-Greenslade.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a08a02a07a02/Turkoise-by-Joan-M-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a05a06a08a08a03/Waiting-for-Butterflies-by-Karen-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a01a08a05a03a01/Stowaway-by-Lawrence-Sargent-Hall.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a03a06a07a04a04/Interpreting-Sargent-by-Elizabeth-Prettejohn.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a05a07a09a01/The-Shore-of-Women-by-Pamela-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a05a05a05a08a08/Garth-of-Izar-by-Pamela-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a06a04a00a07a07/Venus-of-Shadows-by-Pamela-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a06a01a03a01a06/Venus-of-Dreams-by-Pamela-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a09a03a05a08/The-Story-Of-Charles-Ogilvie-by-George-E-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a03a09a01a01a06/Ursula-Unwinds-Her-Anger-by-Kristina-Marcelli-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a07a07a07a00/John-Singer-Sargent-The-Sensualist-by-Trevor-J-Fairbrother.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a05a07a01a05/Mouse-Moments---A-Humorous-Guide-Through-Disneyland-by-Deirdre-A-Sargent.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a08a05a09a04a04/John-Singer-Sargent-Portraits-of-the-1890s-Complete-Paintings-Volume-II-by-Richard-Ormond.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a02a03a00a05/Eleven-Days-An-Unexpected-Love-Days-Trilogy-1-by-Lora-Lindy.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a08a02a08a03a08/School-Days-and-Steam-Days-The-Trainspotting-Adventures-of-Paul-Carr-by-Barry-Allen.pdfIn PDF document text