Malicious PDF — malware analysis report

Static analysis result for SHA-256 11877bf24b4a14d0…

MALICIOUS

PDF

17.1 KB Created: 2019-11-07 15:51:35 +00:00 Authoring application: mPDF 5.7
MD5: 8f9c9baeef2524dd35fd72cade3c360c SHA-1: 9bc8e237888f4e5365f4ae98c20e38e358440656 SHA-256: 11877bf24b4a14d0d46c4f647b91c317c517720da76cfc341172d1c875babd11
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be directing users to a large collection of external PDF files, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/7736735730737739/Middle-Earth-Role-Playing-by-S-Coleman-Charlton.pdf
    • http://cefasfese.4pu.com/1738735736739732/The-Shaping-of-Middle-earth-The-History-of-Middle-earth-4-by-J-R-R-Tolkien.pdf
    • http://cefasfese.4pu.com/1739733738730737/Serenity-Role-Playing-Game-by-Jamie-Chambers.pdf
    • http://cefasfese.4pu.com/6736735738735739/The-History-of-Middle-Earth-Index-The-History-of-Middle-Earth-13-by-J-R-R-Tolkien.pdf
    • http://cefasfese.4pu.com/7737732733739734/Over-the-Edge-The-Role-Playing-Game-of-Surreal-Danger-by-Jonathan-Tweet.pdf
    • http://cefasfese.4pu.com/1739733737738735/Diaspora-Hard-Science-Fiction-Role-Playing-with-Fate-by-B-Murray.pdf
    • http://cefasfese.4pu.com/9738731736734732/Live-and-Let-Die-James-Bond-007-role-playing-game-by-Gerard-Christopher-Klug.pdf
    • http://cefasfese.4pu.com/8731731730735735/Spells-amp-Favours-For-Mythic-Fantasy-Role-Playing-Game-by-Varg-Vikernes.pdf
    • http://cefasfese.4pu.com/2730733735739731/Fault-Lines-The-Layman-s-Guide-to-Understanding-America-s-Role-in-the-Ever-Changing-Middle-East-by-Don-Liebich.pdf
    • http://cefasfese.4pu.com/2737733732730731/One-Last-Good-Day-Eelings-Rare-Earth-1-by-Kimberly-Coleman.pdf
    • http://cefasfese.4pu.com/6736735739731738/The-Histories-of-Middle-Earth-Volumes-1-5-by-J-R-R-Tolkien.pdf
    • http://cefasfese.4pu.com/1731736731736739739/The-Roadkill-of-Middle-Earth-by-John-Carnell.pdf
    • http://cefasfese.4pu.com/2736736739738/Visions-of-Middle-Earth-by-Donato-Giancola.pdf
    • http://cefasfese.4pu.com/6736735739731739/J-R-R-Tolkien-Architect-of-Middle-Earth-by-Daniel-Grotta.pdf
    • http://cefasfese.4pu.com/1738730737731735/The-Atlas-of-Middle-Earth-by-Karen-Wynn-Fonstad.pdf
    • http://cefasfese.4pu.com/3734739736736731/Pandemonium-Middle-Earth-The-Secret-History-1-by-Richard-Warren.pdf
    • http://cefasfese.4pu.com/3734732731735730/Tolkien-Trivia-A-Middle-Earth-Miscellany-by-William-C-MacKay.pdf
    • http://cefasfese.4pu.com/1732739737733732/Tolkien-s-Legendarium-Essays-on-the-History-of-Middle-Earth-by-Verlyn-Flieger.pdf
    • http://cefasfese.4pu.com/4738733733730736/The-Book-of-Lost-Tales-Part-One-The-History-of-Middle-Earth-1-by-J-R-R-Tolkien.pdf
    • http://cefasfese.4pu.com/3734739736737731/Of-Elf-maidens-and-Men-Middle-Earth-The-Secret-History---The-Scented-Garden-4-by-Richard-Warren.pdf