Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ba285a187fd92b3…

MALICIOUS

PDF

26.8 KB Created: 2019-05-03 23:22:21 +01:00 Authoring application: mPDF 5.7
MD5: 3bbe84cfd5c82775bc3ad5cb56bd4025 SHA-1: b299c793ce7e1998accc7aa1d546a6105f410dfa SHA-256: 0ba285a187fd92b30a505f8efead7c25133cbef7716c490ae03bb7b197ecb63b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/6731739736730739/The-Meditation-Bible-Godsfield-Bibles-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/6731739734735738/The-Meditation-Experience-Your-Complete-Meditation-Workshop-in-a-Book-with-a-CD-of-Meditations-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/6731739735732730/Working-with-Meditation-Practical-Ways-to-Heal-and-Transform-Your-Life-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/6731739736739737/Biblia-de-los-signos-y-de-los-simbolos-Bible-of-the-Signs-and-Symbols-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/6731739735732732/Personal-Power-Animals-For-Guidance-Protection-and-Healing-by-Madonna-Gauding.pdf
    • http://cefasfese.4pu.com/2739738733731731/America-s-First-Bibles-With-A-Census-Of-555-Extant-Bibles-by-Edwin-A-R-Rumball-Petre.pdf
    • http://cefasfese.4pu.com/1730734735737737734/Tiefe-Zen-Meditation-Sofortig-Tiefste-Meditation-Stressabbau-und-Selbstheilung-Tiefen-Zustand-der-Meditation-in-Minuten-by-Sharon-Hoover.pdf
    • http://cefasfese.4pu.com/4731737739738739/Meditation-XVII---Meditation-17-by-John-Donne.pdf
    • http://cefasfese.4pu.com/1731738730734732732/Tagging-the-Bible-How-to-unlock-understand-and-find-help-in-the-Bible-using-a-new-approach-to-Inductive-Bible-Study-a-guide-for-beginners-of-all-beliefs-by-Ulf-Preisler.pdf
    • http://cefasfese.4pu.com/1731734739736732739/Meditation-Meditieren-lernen-mit-einfachen-Meditationstechniken-die-Stress-abbauen-innere-Unruhe-und-Depression-beseitigen-so-dass-du-jetzt-gl-cklich-Meditation-Buddhismus-by-Sebi-Heindl.pdf
    • http://cefasfese.4pu.com/8730737737732739/King-James-The-Holy-Bible-the-bible-bible-bible-study-jesus-religion-religious-heaven-king-james-old-testament-new-testament-prayer-books-christian-by-Anonymous.pdf
    • http://cefasfese.4pu.com/9731732739737736/Inspired-By-The-Bible-Experience-The-Complete-Bible-Audio-CD-A-Dramatic-Audio-Bible-Performed-by-400-of-Today-s-Biggest-Stars-by-Anonymous.pdf
    • http://cefasfese.4pu.com/8739738733737733/The-Book-of-Bibles-by-Stephan-Fussel.pdf
    • http://cefasfese.4pu.com/7736731734730730/The-Tijuana-Bibles-Volume-2-by-Michael-Dowers.pdf
    • http://cefasfese.4pu.com/5739736737738734/Mille-et-une-bibles-du-sexe-by-Yambo-Ouologuem.pdf
    • http://cefasfese.4pu.com/7736731733739736/Tijuana-Bibles-Art-and-Wit-in-America-s-Forbidden-Funnies-1930s-1950s-by-Bob-Adelman.pdf
    • http://cefasfese.4pu.com/3734730735731736/Holy-Bible-The-Green-Bible-New-Revised-Standard-Version-by-Anonymous.pdf
    • http://cefasfese.4pu.com/9738736731737735/You-Can-Understand-the-Bible-A-Practical-Guide-to-Each-Book-in-the-Bible-by-Peter-Kreeft.pdf
    • http://cefasfese.4pu.com/7736733736734732/Holy-Bible-Wild-About-Horses-Bible-New-Internation-Version-by-Anonymous.pdf
    • http://cefasfese.4pu.com/1730731736734734/Step-Into-the-Bible-100-Bible-Stories-for-Family-Devotions-by-Ruth-Graham.pdf