Malicious PDF — malware analysis report

Static analysis result for SHA-256 f96fa06495fb54c9…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 05:34:27 +01:00 Authoring application: mPDF 5.7 First seen: 2021-08-25
MD5: 0b90d1643a298bcad3567a5478fa6be1 SHA-1: fba9c369ef54b2393deccf0f609988a4226e1469 SHA-256: f96fa06495fb54c9e530a4cb878e77d60d103b003d3edc9ecac8c15abf589026
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to other PDF files, identified as a link farm. While the ML classifier flagged it as malicious, the specific URLs extracted are currently marked as benign. The presence of a 'download button' lure and the overall structure suggest an attempt to direct users to external content, potentially for malicious purposes like malware distribution or SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/1a03a08a09a09a06/The-Greatness-of-the-Kingdom-An-Inductive-Study-of-the-Kingdom-of-God-by-Alva-J-McClain.pdf In PDF document text
    • http://muicuiu.dumb1.com/7a07a03a06a00a09/Kingdom-Principles-Preparing-for-Kingdom-Experience-and-Expansion-by-Myles-Munroe.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a06a01a03a03a02/Articles-on-Old-Kingdom-Series-Including-Sabriel-Lirael-Abhorsen-Across-the-Wall-A-Tale-of-the-Abhorsen-and-Other-Stories-Old-Kingdom-Book-Ser-by-Hephaestus-Books.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a06a03a04a02a00/The-Hollow-Kingdom-Book-I----The-Hollow-Kingdom-Trilogy-by-Clare-B-Dunkle.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a03a03a09a05a02/Kingdom-of-Abel---Bathed-in-Shadow-Kingdom-of-Abel-3-by-Gume-Laurel-III.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a06a06a01a04a04/The-Hidden-Magic-of-Walt-Disney-World-Over-600-Secrets-of-the-Magic-Kingdom-Epcot-Disney-s-Hollywood-Studios-and-Animal-Kingdom-by-Susan-Veness.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a01a07a00a06a00/The-Canticle-Kingdom-The-Canticle-Kingdom-1-by-Michael-D-Young.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a04a00a02a04a04/Kingdom-Tales-Kingdom-Tales-1-3-by-David-R-Mains.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a01a00a04a05a05/The-Kingdom-and-the-Crown-Set-The-Kingdom-and-the-Crown-1-3-by-Gerald-N-Lund.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a03a02a07a00a00/Magic-Kingdom-for-Sale-1-5-Magic-Kingdom-for-Sale-1-5-by-Terry-Brooks.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a07a08a04a08a09/The-Kingdom-of-God-Is-Within-You-by-Leo-Tolstoy.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a05a03a01a01a03/The-Kingdom-of-the-Air-by-C-T-Wells.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a00a01a09a03a00/To-the-Sky-Kingdom-by-Tang-Qi.pdfIn PDF document text
    • http://muicuiu.dumb1.com/8a05a04a08a06/In-the-Kingdom-of-Men-by-Kim-Barnes.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a02a02a04a08/Hockey-Wives-Box-Set-by-S-M-Kingdom.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a01a03a08a03a04/Our-Lives-in-the-Light-by-Amy-Kingdom.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a06a07a00a02a00/A-Kingdom-by-James-Hanley.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a06a03a02a04a01/The-Gem-Kingdom-by-Paul-E-Desautels.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a02a01a03a04a04/In-the-Kingdom-of-Ice-by-Hampton-Sides.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a02a05a00a05a08/Crap-Kingdom-by-D-C-Pierson.pdfIn PDF document text