Malicious PDF — malware analysis report

Static analysis result for SHA-256 00cc2066564e080c…

MALICIOUS

PDF

16.7 KB Created: 2019-11-21 12:47:26 +00:00 Authoring application: mPDF 5.7
MD5: 3433b7bff77dd98c35e074245360077e SHA-1: 403f25eabe9d926c54d66120ccbbbab634e75b35 SHA-256: 00cc2066564e080cefce146db79079612e05617df04421e86915cbb01f191f4b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. This suggests the document's primary purpose is to redirect users to external sites, potentially for SEO poisoning or to host malicious content. ClamAV also identified this as a 'Pdf.Dropper.Agent', indicating a potential for dropping further malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9810

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7531856-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7531856-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3739730736738736/The-Last-Four-Things-The-Left-Hand-of-God-2-by-Paul-Hoffman.pdf
    • http://cefasfese.4pu.com/4734738737738/The-Last-Four-Things-The-Left-Hand-of-God-2-by-Paul-Hoffman.pdf
    • http://cefasfese.4pu.com/4734732734732733/The-Left-Hand-of-God-by-Paul-Hoffman.pdf
    • http://cefasfese.4pu.com/4738735731735734/The-Left-Hand-of-God-by-Hugh-Holton.pdf
    • http://cefasfese.4pu.com/2737732737734736/The-Left-Hand-of-Darkness-by-Ursula-K-Le-Guin.pdf
    • http://cefasfese.4pu.com/9739730732736733/The-Left-Hand-of-Destiny-Book-One-by-J-G-Hertzler.pdf
    • http://cefasfese.4pu.com/7737739731735/Aghora-At-the-Left-Hand-of-God-by-Robert-E-Svoboda.pdf
    • http://cefasfese.4pu.com/4738736738732737/The-Left-Hand-Of-Darkness-by-Ursula-K-Le-Guin.pdf
    • http://cefasfese.4pu.com/3738731739736737/The-Left-Hand-of-the-Electron-by-Isaac-Asimov.pdf
    • http://cefasfese.4pu.com/3730737733735733/The-Left-Hand-of-Darkness-by-Ursula-K-Le-Guin.pdf
    • http://cefasfese.4pu.com/2738737731736737/Pretty-Little-Things-by-Jilliane-Hoffman.pdf
    • http://cefasfese.4pu.com/2738737736730739/Pretty-Little-Things-by-Jilliane-Hoffman.pdf
    • http://cefasfese.4pu.com/1736733737738734/The-Small-Heart-of-Things-Being-at-Home-in-a-Beckoning-World-by-Julian-Hoffman.pdf
    • http://cefasfese.4pu.com/8732738732735737/Things-Left-Behind-by-Gary-A-Braunbeck.pdf
    • http://cefasfese.4pu.com/4730735737732738/Demons-of-the-Flesh-The-Complete-Guide-to-Left-Hand-Path-Sex-Magic-by-Nikolas-Schreck.pdf
    • http://cefasfese.4pu.com/9739737735737733/Things-Left-Unspoken-by-Eva-Marie-Everson.pdf
    • http://cefasfese.4pu.com/1736733738733731/Rocannon-s-World-Planet-of-Exile-City-of-Illusions-The-Left-Hand-of-Darkness-by-Ursula-K-Le-Guin.pdf
    • http://cefasfese.4pu.com/3736732731735734/The-Invisible-Hand-Do-All-Things-Really-Work-for-Good-by-R-C-Sproul.pdf
    • http://cefasfese.4pu.com/4736730734737738/Commies-A-Journey-Through-the-Old-Left-the-New-Left-and-the-Leftover-Left-by-Ronald-Radosh.pdf
    • http://cefasfese.4pu.com/4739738733736734/Danzig-Hidden-Lyrics-of-The-Left-Hand-by-Glenn-Danzig.pdf