Malicious PDF — malware analysis report

Static analysis result for SHA-256 13c53befec9e40a1…

MALICIOUS

PDF

17.6 KB Created: 2019-05-03 16:11:20 +01:00 Authoring application: mPDF 5.7
MD5: 5d7d90287c1eec58b8e60d23936c0b2f SHA-1: 8dff7ea60f5bb24db628cb37dc86fe5be940a142 SHA-256: 13c53befec9e40a1e96589cb41e19334a36d352d5f3a2ea6b573f99368ef777a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which suggests an attempt to drive traffic to external sites. While the document body is heavily obfuscated, the presence of numerous links indicates a potential SEO poisoning or link farm attack. The ML classifier also flagged the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9344

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1731737733735738739/Panama-By-Locals---A-Panama-Travel-Guide-Written-By-A-Panamanian-The-Best-Travel-Tips-About-Where-to-Go-and-What-to-See-in-Panama-by-Guides-by-Locals.pdf
    • http://cefasfese.4pu.com/5739731737732739/Naples-By-Locals---A-Naples-Pompeii-and-The-Amalfi-Coast-Travel-Guide-Written-By-A-Local-by-Guides-by-Locals.pdf
    • http://cefasfese.4pu.com/1731737733734735731/Panama-by-Kevin-Buckley.pdf
    • http://cefasfese.4pu.com/1731737733735738735/Panama-by-Christopher-P-Baker.pdf
    • http://cefasfese.4pu.com/1731737733736735730/Panama-Girl-by-Ida-Freer.pdf
    • http://cefasfese.4pu.com/3732734730737737/Panama-by-Shelby-Hiatt.pdf
    • http://cefasfese.4pu.com/1731737733736735732/Panama-by-Christopher-Baker.pdf
    • http://cefasfese.4pu.com/3733737737737734/Limitless-Travel-Tips-Strategies-and-Resources-for-Cheaper-and-Smarter-Travel-by-Matthew-Bailey.pdf
    • http://cefasfese.4pu.com/1731737733736734730/Panama-1989-90-by-Gordon-L-Rottman.pdf
    • http://cefasfese.4pu.com/1731737733734739737/Panama-by-Carlos-Ledson-Miller.pdf
    • http://cefasfese.4pu.com/4739734734730737/The-Sack-of-Panama-by-Peter-Earle.pdf
    • http://cefasfese.4pu.com/5738730734731730/Cruising-Panama-s-Canal-by-Al-Lockwood.pdf
    • http://cefasfese.4pu.com/3738736739735/The-Panama-Laugh-by-Thomas-S-Roche.pdf
    • http://cefasfese.4pu.com/1730735736732738735/Message-from-Panama-by-Britt-Vasarhelyi.pdf
    • http://cefasfese.4pu.com/1731737733735738736/The-Panama-Portrait-by-Stanley-Ellin.pdf
    • http://cefasfese.4pu.com/1731737733735738730/Frommer-s-Panama-by-Jisel-Perilla.pdf
    • http://cefasfese.4pu.com/1731734730738737737/Pyjama-rel-in-Panama-Bob-Evers-21-by-Willy-van-der-Heide.pdf
    • http://cefasfese.4pu.com/1731737733735739730/Panama-Passage-by-Donald-Barr-Chidsey.pdf
    • http://cefasfese.4pu.com/1731737733735730733/The-Pirate-Of-Panama-by-William-MacLeod-Raine.pdf
    • http://cefasfese.4pu.com/1731737733737730736/From-Barbados-to-Panama-by-Melva-Lowe-De-Goodin.pdf