Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef5a9c7c7dbbaace…

MALICIOUS

PDF

21.6 KB Created: 2019-04-30 06:12:07 +01:00 Authoring application: mPDF 5.7 First seen: 2021-08-20
MD5: a1c395651fa9a32609770eecbf98632a SHA-1: 5761488c07bf16ec497c7774d4f41e777b94a8fe SHA-256: ef5a9c7c7dbbaacebdd1e7f8a891ef5d8a9f191f7fdc50455f461d2d48c8e521
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a PDF that contains a large number of embedded links to other PDF files, suggesting a link farm or SEO poisoning attempt. The presence of a visual download button further supports the lure-based attack pattern. While no scripts were explicitly extracted, the PDF structure and embedded URLs indicate a potential for malicious content delivery, likely through a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a01a03a05a03a04/Hide-The-Delta-Project-1-by-Jessica-Jaster.pdf In PDF document text
    • http://muicuiu.dumb1.com/4a08a08a03a04a09/Delta-Autumn-A-guide-for-First-Year-Teachers-in-the-Mississippi-Delta-by-Andrew-P-Mullins-Jr-.pdfIn PDF document text
    • http://muicuiu.dumb1.com/7a08a03a04a06a07/Delta-Rescue-Delta-2-5-The-MacKenzie-Family-10-5-by-Cristin-Harber.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a09a03a00/Delta-Retribution-Delta-1-by-Cristin-Harber.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a09a05a02a05a02/Hide-Alex-Hide-by-Natalie-Finnigan.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a09a05a02a06a05/Hide-Omnibus-Hide-1-5-by-Jax-Spenser.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a02a01a02a02a05/Hide-and-Seek-Hide-and-Seek-Mystery-Series-1-by-Jennifer-Hayden.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a09a05a03a07/Touch-by-Natalia-Jaster.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a00a07a02a04a08/Touch-by-Natalia-Jaster.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a02a03a09a01a08/Halo-Fanon---The-Parkster-Bauxite-Cn-Military-Cleansing-Truth-Conan-G037-Delta-7-Division-Delta-Kanteon-System-Drakos-Galax-Solaray-in-Military-Imprisonment-Jake-G239-Jiralhanae-Jun-A266-Keonlex-Keonprimal-City-Libra-Team-M3a-S3d7-Comba-by-Source-Wikia.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a02a06a02a04a02/Dare-Foolish-Kingdoms-2-by-Natalia-Jaster.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a00a09a04a06/The-Ultimate-Tree-House-Project-Project-Kids-Adventure-1-by-Gary-M-Nelson.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a00a09a04a09/Results-Without-Authority-Controlling-a-Project-When-the-Team-Doesn-t-Report-to-You---A-Project-Manager-s-Guide-by-Tom-Kendrick.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a01a05a00a07a00a02/Revised-An-Introduction-to-Project-Management-With-Brief-Guides-to-Microsoft-Project-2010-and-task-by-Kathy-Schwalbe.pdfIn PDF document text
    • http://muicuiu.dumb1.com/9a05a02a04a04a02/A-Guide-to-the-Project-Management-Body-of-Knowledge-Dritte-Ausgabe-by-Project-Management-Institute.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a00a09a00a01/A-Guide-to-the-Project-Management-Body-of-Knowledge-by-Project-Management-Institute.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a09a07a08a08/Watch-Over-Me-Mercenary-Goddard-Project-9-Goddard-Project-4-by-Lucy-Monroe.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a06a07a00a05/To-Live-and-To-Love-Black-Wolf-Agency-1-by-Jessica-Musso-Jessica-Lupo-.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a06a07a01a04/Shadows-of-the-Moon-Black-Wolf-Agency-2-by-Jessica-Musso-Jessica-Lupo-.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a05a06a06a09a04/The-Heart-of-the-Rougarou-The-Secret-of-Wolf-River-1-by-Jessica-Musso-Jessica-Lupo-.pdfIn PDF document text