Malicious PDF — malware analysis report

Static analysis result for SHA-256 0884d5dd48e816e3…

MALICIOUS

PDF

18.2 KB Created: 2019-11-28 22:38:52 +00:00 Authoring application: mPDF 5.7
MD5: eb071eac7727b00388226b085f134b03 SHA-1: bf63ab47435f34637817b7f155aca854f53999b7 SHA-256: 0884d5dd48e816e33a7a8f1ee77e2c0e032de0a16a952c134e4c011fc9e0a207
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to direct users to external resources. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/5735739732735736/Princess-of-the-Midnight-Ball-The-Princesses-of-Westfalin-Trilogy-1-by-Jessica-Day-George.pdf
    • http://cefasfese.4pu.com/4733731735736738/Princess-of-the-Midnight-Ball-The-Princesses-of-Westfalin-Trilogy-1-by-Jessica-Day-George.pdf
    • http://cefasfese.4pu.com/3738730730732/Princess-of-the-Silver-Woods-The-Princesses-of-Westfalin-Trilogy-3-by-Jessica-Day-George.pdf
    • http://cefasfese.4pu.com/1739739736732734/Princess-of-Glass-The-Princesses-of-Westfalin-2-by-Jessica-Day-George.pdf
    • http://cefasfese.4pu.com/6730735736736/The-Complete-Princess-Trilogy-Princess-Princess-Sultana-s-Daughters-and-Princess-Sultana-s-Circle-by-Jean-Sasson.pdf
    • http://cefasfese.4pu.com/1732730735730/The-Barefoot-Princess-Lost-Princesses-2-by-Christina-Dodd.pdf
    • http://cefasfese.4pu.com/4738731736735739/To-Be-a-Princess-The-Fascinating-Lives-of-Real-Princesses-by-Hugh-Brewster.pdf
    • http://cefasfese.4pu.com/2730734733737738/The-Highlander-s-Princess-Bride-The-Improper-Princesses-3-by-Vanessa-Kelly.pdf
    • http://cefasfese.4pu.com/8732731732730737/Jahanara-Princess-Of-Princesses-India-1627-The-Royal-Diaries-12-by-Kathryn-Lasky.pdf
    • http://cefasfese.4pu.com/3733737736730736/The-Kiss-after-Midnight-The-Midnight-Trilogy-1-by-Marvin-Amazon.pdf
    • http://cefasfese.4pu.com/7737737732/Ash-Princess-Ash-Princess-Trilogy-1-by-Laura-Sebastian.pdf
    • http://cefasfese.4pu.com/7730735732734738/Ash-Princess-Ash-Princess-Trilogy-1-by-Laura-Sebastian.pdf
    • http://cefasfese.4pu.com/4730737737734731/Midnight-Graffiti-by-Jessica-Horsting.pdf
    • http://cefasfese.4pu.com/7738733730738733/Dark-Desires-at-Midnight-The-Enclave-2-by-Jessica-Lee.pdf
    • http://cefasfese.4pu.com/5736736737739736/Tiger-by-the-Tail-Midnight-Liaisons-4-5-by-Jessica-Sims.pdf
    • http://cefasfese.4pu.com/7734736730/At-the-Stroke-of-Midnight-The-Naughty-Princess-Club-1-by-Tara-Sivec.pdf
    • http://cefasfese.4pu.com/1734734738739733/Beauty-Dates-the-Beast-Midnight-Liaisons-1-by-Jessica-Sims.pdf
    • http://cefasfese.4pu.com/4739732736734733/Wanted-Wild-Thing-Midnight-Liaisons-4-by-Jessica-Sims.pdf
    • http://cefasfese.4pu.com/3732733730735732/His-Royal-Princess-Billionaire-Boys-Club-3-5-by-Jessica-Clare.pdf
    • http://cefasfese.4pu.com/3739734731737739/Midnight-s-Tale-by-George-Berger.pdf