Malicious PDF — malware analysis report

Static analysis result for SHA-256 069e98aba45ca5b9…

MALICIOUS

PDF

17.4 KB Created: 2019-05-24 17:47:20 +01:00 Authoring application: mPDF 5.7
MD5: b23b7ee0250a82c7cccbfea089630c26 SHA-1: c4b52d3e4fb6b52fb9004cefd7a81389830e6be6 SHA-256: 069e98aba45ca5b90843ccaa8325aeaf21996de0fe1937b65a19f71246011216
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, directing users to external PDF documents. While the document body is heavily obfuscated, the heuristic firings strongly suggest a malicious intent to redirect users to potentially harmful content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7733731736735738/Objections-to-Christian-Belief-by-A-R-Vidler.pdf
    • http://cefasfese.4pu.com/7733731736735737/But-Is-It-Real-Answering-10-Common-Objections-to-the-Christian-Faith-by-Amy-Orr-Ewing.pdf
    • http://cefasfese.4pu.com/7733731735736733/Objections-Objections-Objections-by-Gavin-Ingham.pdf
    • http://cefasfese.4pu.com/7733731735736734/Any-Objections-by-Mario-Testino.pdf
    • http://cefasfese.4pu.com/7733731735736739/Objections-to-Humanism-by-H-J-Blackham.pdf
    • http://cefasfese.4pu.com/7733731736735732/Objections-At-Trial-by-Myron-H-Bright.pdf
    • http://cefasfese.4pu.com/7733731735735737/Affidavit-of-Objections-by-William-Hayden.pdf
    • http://cefasfese.4pu.com/7733731736732734/Objections-to-Calvinism-by-Randolph-Sinks-Foster.pdf
    • http://cefasfese.4pu.com/7733731736731735/Meditations-Objections-and-Replies-by-Ren-Descartes.pdf
    • http://cefasfese.4pu.com/7733731737734739/Trial-Objections-Handbook-2D-by-Roger-C-Park.pdf
    • http://cefasfese.4pu.com/7733731736736731/MLM-SCRIPTS-Recruiting-and-Handling-Objections-by-Lewis-Smile.pdf
    • http://cefasfese.4pu.com/7733731736731736/Answering-the-Objections-of-Atheists-Agnostics-amp-Skeptics-by-Ron-Rhodes.pdf
    • http://cefasfese.4pu.com/7733731736732732/No-Objections-Harlequin-Romance-3281-by-Kate-Denton.pdf
    • http://cefasfese.4pu.com/7733731737734735/Nullification-Objections-Dismantling-the-Opposition-by-Michael-Maharrey.pdf
    • http://cefasfese.4pu.com/7733731736736730/25-Toughest-Sales-Objections-And-How-to-Overcome-Them-by-Stephan-Schiffman.pdf
    • http://cefasfese.4pu.com/7733731737735736/Letters-to-the-Editor-Opinions-Objections-and-Recollections-by-Richard-Lettis.pdf
    • http://cefasfese.4pu.com/7733731736738733/Objection-Game---Conquer-the-Five-Deadly-Objections-and-Have-Sex-with-a-Woman-Even-if-she-s-not-attracted-to-you-by-Vin-DiCarlo.pdf
    • http://cefasfese.4pu.com/6731735732734735/Belief-and-the-Nation-by-John-Scriven.pdf
    • http://cefasfese.4pu.com/4731730735738738/A-Quiet-Belief-in-Angels-by-R-J-Ellory.pdf
    • http://cefasfese.4pu.com/7730738738732733/The-Christian-Remembrancer-or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf