Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a56bda57edec81d…

MALICIOUS

PDF

18.8 KB Created: 2019-05-26 17:07:09 +01:00 Authoring application: mPDF 5.7
MD5: 5f8642ab19c4000feebf0b5b04717fc5 SHA-1: 7be8953ca9aab95e5f4c85e9ef99e2a2f04388eb SHA-256: 0a56bda57edec81d2c9545bc90d4bde8a4ee6a04299dc0034b0d4d34efe91a61
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single suspicious domain, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The embedded URLs are likely part of a link farm designed to manipulate search engine results or redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3736731732735734/A-Very-Dark-Place-Dead-End-4-by-P-S-Power.pdf
    • http://cefasfese.4pu.com/4731735737737736/Power-and-Place-Indian-Education-in-America-by-Vine-Deloria-Jr-.pdf
    • http://cefasfese.4pu.com/4734737732738734/Conversations-with-the-Goddess-Encounter-at-Petra-Place-of-Power-by-Dorothy-Atalla.pdf
    • http://cefasfese.4pu.com/1730730736736734739/Tahiti-Beyond-the-Postcard-Power-Place-and-Everyday-Life-by-Miriam-Kahn.pdf
    • http://cefasfese.4pu.com/6732732731733733/The-Power-of-Place-Urban-Landscapes-as-Public-History-by-Dolores-Hayden.pdf
    • http://cefasfese.4pu.com/6735734739730736/Lex-Rex-The-Law-the-King-A-Biblical-Primer-on-the-Purpose-Place-and-Power-of-Civil-Government-by-Thomas-Adamo.pdf
    • http://cefasfese.4pu.com/1732737730734739/Running-Through-a-Dark-Place-Children-of-the-Knight-2-by-Michael-J-Bowler.pdf
    • http://cefasfese.4pu.com/3738739734733734/A-Cold-Dark-Place-Emily-Kenyon-1-by-Gregg-Olsen.pdf
    • http://cefasfese.4pu.com/1734734735736730/A-Dark-Place-in-the-Jungle-Following-Leakey-s-Last-Angel-Into-Borneo-by-Linda-Spalding.pdf
    • http://cefasfese.4pu.com/2738736734733734/Dark-Needs-Power-Series-1-amp-2-by-Mychael-Black.pdf
    • http://cefasfese.4pu.com/4737730732734732/Dark-Visions-The-Strange-Power-The-Possessed-The-Passion-by-L-J-Smith.pdf
    • http://cefasfese.4pu.com/2735731730739737/Dead-Dwight-a-dark-comedy-by-E-V-Iverson.pdf
    • http://cefasfese.4pu.com/2739738738731733/Bring-Out-Your-Dead-Dark-Ones-4-5-by-Katie-MacAlister.pdf
    • http://cefasfese.4pu.com/4739739733739732/Dark-Star-Rising-Magick-and-Power-in-the-Age-of-Trump-by-Gary-Lachman.pdf
    • http://cefasfese.4pu.com/1730730733739737734/Dark-Ghetto-Dilemmas-of-Social-Power-by-Kenneth-Bancroft-Clark.pdf
    • http://cefasfese.4pu.com/4739730734731731/Dead-Until-Dark-Sookie-Stackhouse-1-by-Charlaine-Harris.pdf
    • http://cefasfese.4pu.com/2734735738736736/The-Dog-in-the-Dark-Noble-Dead-Saga-Series-3-2-by-Barb-Hendee.pdf
    • http://cefasfese.4pu.com/8731735734730736/Work-Clean-The-life-changing-power-of-mise-en-place-to-organize-your-life-work-and-mind-by-Dan-Charnas.pdf
    • http://cefasfese.4pu.com/5735739733738735/Dead-of-Night-Dancers-in-the-Dark-The-Devil-s-Footprints-by-Charlaine-Harris.pdf
    • http://cefasfese.4pu.com/3735732734738733/Stories-of-the-Raksura-Volume-Two-The-Dead-City-amp-The-Dark-Earth-Below-by-Martha-Wells.pdf