Malicious PDF — malware analysis report

Static analysis result for SHA-256 04faf524f19680ee…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 17:40:03 +01:00 Authoring application: mPDF 5.7
MD5: 9f9c22a3e57e6f25ded884122cd5c3b1 SHA-1: 3f9585a23e82f72b85f84ccc1692192f0ae63330 SHA-256: 04faf524f19680eedbb50d9e1a77f5ada4a5856dfbccb03c304128e2108ccab7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external websites. While the document body is heavily obfuscated, the presence of these links suggests an attempt to redirect users to potentially malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/4b27b26b26b21b26/America-s-Mistress-The-Life-and-Times-of-Eartha-Kitt-by-John-Williams.pdf
    • http://cmeinasaoo.duckdns.org/4b20b21b21b25b27/England-s-Mistress-The-Infamous-Life-of-Emma-Hamilton-by-Kate-Williams.pdf
    • http://cmeinasaoo.duckdns.org/3b20b22b25b25b26/The-Richest-Woman-in-America-The-Life-and-Times-of-Hetty-Green-by-Janet-Wallach.pdf
    • http://cmeinasaoo.duckdns.org/1b28b23b22b21/Barney-Oldfield-The-Life-and-Times-of-America-s-Legendary-Speed-King-by-William-F-Nolan.pdf
    • http://cmeinasaoo.duckdns.org/3b23b24b26b29b27/Master-Detective-The-Life-and-Crimes-of-Ellis-Parker-America-s-Real-Life-Sherlock-Holmes-by-John-Reisinger.pdf
    • http://cmeinasaoo.duckdns.org/4b20b23b27b24b27/The-Life-and-Times-of-Richard-J-Hughes-The-Politics-of-Civility-by-John-Wefing.pdf
    • http://cmeinasaoo.duckdns.org/7b26b23b20b23b29/Rebel-The-Life-and-Times-of-John-Singleton-Mosby-by-Kevin-H-Siepel.pdf
    • http://cmeinasaoo.duckdns.org/9b21b24b29b24b21/A-Long-Way-To-The-Top-The-Life-and-Times-of-One-of-the-Lesser-Known-of-the-Lairds-of-John-O-Groats-by-Laird-Tschonnie-Scribbler.pdf
    • http://cmeinasaoo.duckdns.org/4b22b28b22b29b22/Mistresses-The-Italian-s-Inexperienced-Mistress-Emerald-Mistress-Mistress-Bought-and-Paid-For-by-Lynne-Graham.pdf
    • http://cmeinasaoo.duckdns.org/4b27b29b27b21/Diet-for-a-New-America-How-Your-Food-Choices-Affect-Your-Health-Happiness-and-the-Future-of-Life-on-Earth-by-John-Robbins.pdf
    • http://cmeinasaoo.duckdns.org/2b24b20b22b28/Eartha-by-Cathy-Malkasian.pdf
    • http://cmeinasaoo.duckdns.org/4b28b21b29b21b29/Life-in-America-Life-in-America-by-Arnaz-Buckner.pdf
    • http://cmeinasaoo.duckdns.org/4b21b25b22b23b20/Our-Enemies-in-Blue-Police-and-Power-in-America-by-Kristian-Williams.pdf
    • http://cmeinasaoo.duckdns.org/6b25b26b28b21b26/Spies-in-the-Congo-America-s-Atomic-Mission-in-World-War-II-by-Susan-Williams.pdf
    • http://cmeinasaoo.duckdns.org/4b22b28b22b27b29/The-Mysterious-Mistress-The-Life-And-Legend-Of-Jane-Shore-by-Margaret-Crosland.pdf
    • http://cmeinasaoo.duckdns.org/7b25b20b22b24b22/Dogging-Steinbeck-How-I-Went-in-Search-of-John-Steinbeck-s-America-Found-My-Own-America-and-Exposed-the-Truth-about-Travels-with-Charley-by-Bill-Steigerwald.pdf
    • http://cmeinasaoo.duckdns.org/3b28b21b29b27b26/Demeter-s-Daughters-The-Women-Who-Founded-America-1587-1787-by-Selma-R-Williams.pdf
    • http://cmeinasaoo.duckdns.org/5b22b26b22b28b29/Mistress-Peachum-s-Pleasure-The-Life-of-Lavinia-Duchess-of-Bolton-by-Lisa-Hilton.pdf
    • http://cmeinasaoo.duckdns.org/2b26b27b23b23b20/The-Hour-of-Land-A-Personal-Topography-of-America-s-National-Parks-by-Terry-Tempest-Williams.pdf
    • http://cmeinasaoo.duckdns.org/3b28b24b21b29b24/The-Perfect-Mistress-Mistress-2-by-Betina-Krahn.pdf