Malicious PDF — malware analysis report

Static analysis result for SHA-256 f99b006afcaf3bf3…

MALICIOUS

PDF

14.1 KB Created: 2019-04-30 05:36:28 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-17
MD5: 82419420d5ec6e084f6075bc9b30e3d8 SHA-1: fdc6a757a7f04695135b238fa7d3686778481152 SHA-256: f99b006afcaf3bf3926e87bbf1c3084e9a90ad39a7f93fa8eddc140f645e7824
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm that directs users to download other PDF files. This behavior, combined with a critical heuristic firing for PDF_SEO_LINK_FARM and a high ML classification score, indicates a malicious intent to distribute further content. While no scripts were explicitly extracted, the structure suggests a potential for JavaScript execution within the PDF to facilitate downloads, aligning with T1059.007.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/6a05a09a04a06/Crushed-Pretty-Little-Liars-13-by-Sara-Shepard.pdf In PDF document text
    • http://muicuiu.dumb1.com/7a04a08a06a05/Wicked-A-Pretty-Little-Liars-Box-Set-Pretty-Little-Liars-5-8-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a08a09a06a07a08/Pretty-Little-Liars-Pretty-Little-Liars-1-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/2a04a00a08a08a01/Pretty-Little-Liars-Pretty-Little-Liars-1-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a03a05a08/Pretty-Little-Liars-Box-Set-Pretty-Little-Liars-1-4-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a08a02a09a06/Wicked-Pretty-Little-Liars-5-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a09a09a02a08/Wanted-Pretty-Little-Liars-8-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/6a07a05a01a01/Stunning-Pretty-Little-Liars-11-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a04a08a03a07a01/Vicious-Pretty-Little-Liars-16-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a03a03a06a03/Deadly-Pretty-Little-Liars-14-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a05a02a02a02/Flawless-Pretty-Little-Liars-2-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a07a05a05a09a08/Ruthless-Pretty-Little-Liars-10-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/4a05a09a07a00a03/Perfect-Pretty-Little-Liars-3-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a07a08a00a07a01/Dirt-Pretty-Little-Liars-Rosewood-Hotel-Mystery-6-by-M-B-Borchardt.pdfIn PDF document text
    • http://muicuiu.dumb1.com/1a00a07a07a08a07a02/The-A-Game-Pretty-Little-Liars-Rosewood-Hotel-Mystery-5-by-M-B-Borchardt.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a02a09a08a02a05/1-Les-Perfectionnistes-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a04a06a01a00/The-First-Lie-The-Lying-Game-0-5-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a02a09a08a03a02/Les-perfectionnistes---tome-2-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/5a02a09a07a07a04/The-Lying-Game---tome-3-by-Sara-Shepard.pdfIn PDF document text
    • http://muicuiu.dumb1.com/3a07a04a00a02/Two-Truths-and-a-Lie-The-Lying-Game-3-by-Sara-Shepard.pdfIn PDF document text