Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4a2a289d08d9dc3…

MALICIOUS

PDF

14.8 KB Created: 2019-05-01 12:01:23 +01:00 Authoring application: mPDF 5.7
MD5: a5865def023be9741d3ce77376d95536 SHA-1: c6c37c831e0dd4754fe3e902706ae9fed2206726 SHA-256: c4a2a289d08d9dc391f9b4832eff84e794dd432e61a77056ba05211bfac71d11
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links and the ML classifier's high confidence score indicate a malicious intent. The embedded URLs are likely part of a link farm designed to manipulate search engine results or distribute malicious content, potentially using JavaScript for execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/9a05a07a06a01a06/Dragonfyre-Druid-s-Glen-6-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/2a07a09a05a09a00/Highland-Dawn-Druid-s-Glen-3-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/2a08a01a05a08a06/Highland-Dawn-Druid-s-Glen-3-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/4a01a07a06a06a06/Wild-Need-Chiasson-3-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/2a05a04a02a05a01/Heat-Dark-Kings-12-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/3a03a06a00a05a04/The-Protector-Sons-of-Texas-2-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/4a07a04a09/The-Hero-Sons-of-Texas-1-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a01a04a00a04a09a00/Soul-Scorched-Part-4-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/3a08a02a05a01a05/The-Seduced-Rogues-of-Scotland-4-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a00a01a02a08a05a03/A-Kind-of-Magic-The-Shields-2-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a04a05a09a08a01/Wicked-Highlander-Dark-Sword-3-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/4a09a02a09a04a02/Seized-By-Passion-Wicked-Treasures-1-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a03a02a02a09a02/Midnight-s-Master-Dark-Warriors-1-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/3a07a07a00a08a02/Smoldering-Hunger-Dark-Kings-8-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/5a00a08a08a03/Darkest-Highlander-Dark-Sword-6-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a03a00a00a01a01/Midnight-s-Captive-Dark-Warriors-6-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a02a09a03a04a07/Midnight-s-Temptation-Dark-Warriors-7-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a03a01a02a08a06/Midnight-s-Seduction-Dark-Warriors-3-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/1a01a07a09a07a09a06/Flamment-nzer-Ein-Drachenk-nige-Roman-Drachenk-nige-Serie-2-by-Donna-Grant.pdf
    • http://muicuiu.dumb1.com/2a02a02a03a08a08/U-S-Grant-The-Civil-War-Years-Grant-Moves-South-and-Grant-Takes-Command-by-Bruce-Catton.pdf